Magicinfo 9 Server
Vendor:
First CVE: Aug 12, 2024 · Active for 1 year
23
Total CVEs
More Total CVEs than 96% of tracked products
7.7
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
9.7
Avg CVSS
Higher Avg CVSS than 88% of tracked products
8.7%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Magicinfo 9 Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2024
23 months ago
Most Recent CVE
Feb 2, 2026
176 days ago
CVE Severity & Scoring
Magicinfo 9 Server23 CVEs
13%
87%
All CVEs353,240 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (95.7%)
Unknown0 (0.0%)
Required1 (4.3%)
Privileges Required
Low2 (8.7%)
High0 (0.0%)
None21 (91.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7399CRITICAL Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system au | Aug 12, 2024 | 9.8 | 98 | YES | YES |
CVE-2025-4632CRITICAL Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system au | May 13, 2025 | 9.8 | 87 | YES | YES |
CVE-2026-25200CRITICAL A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover
This issue a | Feb 2, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-54449CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.10 | Jul 23, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-54445CRITICAL Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Serv | Jul 23, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-25201HIGH An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server.
This issue affects MagicINFO 9 Server: less than 21 | Feb 2, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-54452CRITICAL Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. | Jul 23, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-54446CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.Thi | Jul 23, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-54441HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.10 | Jul 23, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-25202CRITICAL The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21 | Feb 2, 2026 | 9.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
2 CVEs
8.7% of CVEs· 98th percentile
Metasploit
1 CVE
4.3% of CVEs· 97th percentile
Nuclei
2 CVEs
8.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CWEs
Versions
No cataloged versions.