PT-2025-30538 · Samsung · Magicinfo 9 Server
Published
2025-07-23
·
Updated
2025-07-28
·
CVE-2025-54450
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MagicINFO 9 Server versions prior to 21.1080.0
Description
A path traversal vulnerability exists in Samsung Electronics MagicINFO 9 Server, potentially allowing for code injection. The issue stems from an improper limitation of a pathname to a restricted directory.
Recommendations
Update MagicINFO 9 Server to version 21.1080.0 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magicinfo 9 Server