IoT Security

Samsung MagicINFO Vulnerability Exploited Days After PoC Publication

Threat actors started exploiting a vulnerability in Samsung MagicINFO only days after a PoC exploit was published.

Threat actors started exploiting a vulnerability in Samsung MagicINFO only days after a PoC exploit was published.

The exploitation of a high-severity vulnerability in the Samsung MagicINFO content management system (CMS) began within days after proof-of-concept (PoC) exploit code targeting it was made public, cybersecurity firm Arctic Wolf warns.

Tracked as CVE-2024-7399 (CVSS score of 8.8), the issue is described as an “improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server” that could be exploited to write arbitrary files with system privileges.

Because the CMS does not properly sanitize a filename input, failing to validate the file extension and whether the user is authenticated, an unauthenticated attacker could upload JSP files and execute arbitrary server-side code with system privileges.

“The vulnerability allows for arbitrary file writing by unauthenticated users, and may ultimately lead to remote code execution when the vulnerability is used to write specially crafted JavaServer Pages (JSP) files,” Arctic Wolf notes.

Samsung patched the security defect in MagicINFO 9 Server version 21.1050, which was released in August 2024.

While the company has made no mention of the flaw’s exploitation, Arctic Wolf noticed it being targeted in the wild after a technical writeup and PoC code were published on April 30, 2025.

Advertisement. Scroll to continue reading.

“Given the low barrier to exploitation and the availability of a public PoC, threat actors are likely to continue targeting this vulnerability,” the cybersecurity firm notes.

Organizations and end-users are advised to update to MagicINFO 9 Server version 21.1050 or newer as soon as possible.

An all-in-one solution for content, device, and data management, MagicINFO can be used to create and distribute content to an organization’s linked displays, as well as to remotely manage and secure the displays.

Related: Android Update Patches FreeType Vulnerability Exploited as Zero-Day

Related: Google Warns of Samsung Zero-Day Exploited in the Wild

Related: SonicWall Flags Two More Vulnerabilities as Exploited

Related: Commvault Shares IoCs After Zero-Day Attack Hits Azure Environment

Related Content

Network Security

Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.

Vulnerabilities

The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.

Cybercrime

Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation.

Vulnerabilities

Oracle has released mitigations for CVE-2026-35273, but it has not said whether it’s a zero-day exploited in ShinyHunters attacks.

Vulnerabilities

Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.

Vulnerabilities

The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. 

Vulnerabilities

The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7.

Vulnerabilities

Organizations are advised to apply vendor-supplied mitigations or discontinue the vulnerable devices.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version