Security Flaw in Samsung MagicINFO 9 Server Lets Attackers Write Arbitrary Files

Security Flaw in Samsung MagicINFO 9 Server Lets Attackers Write Arbitrary Files

Samsung has revealed a serious security flaw (CVE-2025-4632) impacting its MagicINFO 9 Server, a popular platform used globally in sectors such as retail, transportation, healthcare, and corporate environments for managing digital signage content.

The vulnerability allows attackers, even without authentication, to write arbitrary files with elevated system-level privileges, potentially leading to a full system takeover.

Path Traversal Issue in Samsung MagicINFO 9

Designated as SVE-2025-50001 in Samsung’s May 2025 security advisory, this flaw has been rated with a CVSS score of 9.8, indicating a critical threat. It affects all versions of Samsung MagicINFO 9 Server before 21.1052.

The flaw arises from what is described as an “improper restriction of pathname access,” where inadequate validation of file paths during write actions lets attackers bypass directory limitations. This allows them to place files anywhere within the system, even in protected system directories, with full SYSTEM user privileges.

This opens the door for attackers to insert malicious code throughout the file system, regardless of intended path restrictions.

The vulnerability closely resembles the CVE-2024-7399 path traversal issue reported in August 2024. Despite Samsung’s claim that version 21.1050 would resolve the earlier flaw, recent findings by security firm Huntress show the patch was ineffective, leaving the system still vulnerable.

Arctic Wolf researchers have already noted attempts to exploit the flaw soon after proof-of-concept code surfaced, suggesting that cybercriminals are actively seeking out and targeting weaknesses in the MagicINFO platform.

Risk FactorsDetails
Affected ProductsSamsung MagicINFO 9 Server versions earlier than 21.1052
ImpactArbitrary file writing with SYSTEM-level privileges, potentially enabling remote code execution
Exploit PrerequisitesRemote access with no authentication required
CVSS 3.1 Score9.8 (CRITICAL)

Mitigation Steps

Samsung has rolled out a security update, SVP-MAY-2025, to fix this vulnerability. As per the details in Samsung’s advisory, the update adjusts the input verification logic. It is highly recommended that users of MagicINFO 9 Server upgrade to version 21.1052 or newer as soon as possible.

Samsung’s policy for SmartTV software updates includes a commitment to provide at least three years of support from the product’s release, alongside ongoing support for critical security patches whenever feasible.

To check for updates, users can navigate to [Settings] → [Support] → [Software Update] directly from the device menu.

MagicINFO is Samsung’s premier platform for managing digital signage, offering a full range of tools for device and content control. It enables management of display content, hardware configurations, and remote troubleshooting capabilities.

Given that MagicINFO operates with high-level system privileges for managing display settings across large-scale networks, the identified vulnerability presents serious security risks to enterprise environments. Exploiting this flaw could allow attackers to implant persistent threats, alter firmware, or even take down entire signage systems.

Experts strongly advise organizations to not only apply the patch but also verify their Auto-Update settings and conduct thorough system audits for any signs of prior compromise.

For those unable to update immediately, it is recommended to isolate MagicINFO systems from external networks until the necessary patches can be installed.

More Articles & Posts