Samsung
Samsung Magicinfo 9 Server: vulnerabilidades y CVE
Samsung Magicinfo 9 Server tiene 24 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 20 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses4
Críticas20
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-7399 | Crítica (9.8) | 92% | ⚠ Explotación activa | 12 ago 2024 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority. |
| CVE-2025-4632 | Crítica (9.8) | 24% | ⚠ Explotación activa | 13 may 2025 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25203 | Alta (7.8) | 0.18% | — | 10 abr 2026 | Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1. |
| CVE-2026-25202 | Crítica (9.8) | 0.48% | — | 2 feb 2026 | The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1. |
| CVE-2026-25201 | Alta (8.8) | 0.45% | — | 2 feb 2026 | An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1. |
| CVE-2026-25200 | Crítica (9.8) | 0.55% | — | 2 feb 2026 | A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than… |
| CVE-2025-54455 | Crítica (9.8) | 0.55% | — | 23 jul 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54454 | Crítica (9.8) | 0.54% | — | 23 jul 2025 | Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54453 | Crítica (9.8) | 24% | — | 23 jul 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54452 | Crítica (9.8) | 0.39% | — | 23 jul 2025 | Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54451 | Crítica (9.8) | 0.65% | — | 23 jul 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54450 | Crítica (9.8) | 0.59% | — | 23 jul 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54449 | Crítica (9.8) | 0.63% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54448 | Crítica (9.8) | 0.60% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54447 | Crítica (9.8) | 0.46% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54446 | Crítica (9.8) | 0.61% | — | 23 jul 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server:… |
| CVE-2025-54445 | Crítica (9.8) | 12% | — | 23 jul 2025 | Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54444 | Crítica (9.8) | 0.60% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54443 | Crítica (9.8) | 0.57% | — | 23 jul 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server:… |
| CVE-2025-54442 | Crítica (9.8) | 0.47% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54441 | Alta (8.8) | 10% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54440 | Crítica (9.8) | 0.50% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54439 | Alta (8.8) | 9.0% | — | 23 jul 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0. |
| CVE-2025-54438 | Crítica (9.8) | 0.61% | — | 23 jul 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server:… |
| CVE-2025-4632 | Crítica (9.8) | 24% | ⚠ Explotación activa | 13 may 2025 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority. |
| CVE-2024-7399 | Crítica (9.8) | 92% | ⚠ Explotación activa | 12 ago 2024 | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.