CVE-2025-4632 is a critical path traversal vulnerability (CWE-22) affecting Samsung MagicINFO 9 Server versions prior to 21.1052. This flaw allows unauthenticated attackers to write arbitrary files with system authority, leading to full compromise of the server. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction required, resulting in complete confidentiality, integrity, and availability impact. This CVE is actively exploited in the wild, notably used to deploy the Mirai botnet, and has a high EPSS score, indicating a significant threat. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, and the vulnerability has garnered substantial community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.1052.0CPE matchmatch criteria | cpe:2.3:a:samsung:magicinfo_9_server:*:*:*:*:*:*:*:* | ||
>= 0, < 21.1052CPE match | cpe:2.3:a:samsung:magicinfo_9_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.