IoT Security

Samsung MagicINFO Vulnerability Exploited Days After PoC Publication

Threat actors started exploiting a vulnerability in Samsung MagicINFO only days after a PoC exploit was published.

Threat actors started exploiting a vulnerability in Samsung MagicINFO only days after a PoC exploit was published.

The exploitation of a high-severity vulnerability in the Samsung MagicINFO content management system (CMS) began within days after proof-of-concept (PoC) exploit code targeting it was made public, cybersecurity firm Arctic Wolf warns.

Tracked as CVE-2024-7399 (CVSS score of 8.8), the issue is described as an “improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server” that could be exploited to write arbitrary files with system privileges.

Because the CMS does not properly sanitize a filename input, failing to validate the file extension and whether the user is authenticated, an unauthenticated attacker could upload JSP files and execute arbitrary server-side code with system privileges.

“The vulnerability allows for arbitrary file writing by unauthenticated users, and may ultimately lead to remote code execution when the vulnerability is used to write specially crafted JavaServer Pages (JSP) files,” Arctic Wolf notes.

Samsung patched the security defect in MagicINFO 9 Server version 21.1050, which was released in August 2024.

While the company has made no mention of the flaw’s exploitation, Arctic Wolf noticed it being targeted in the wild after a technical writeup and PoC code were published on April 30, 2025.

Advertisement. Scroll to continue reading.

“Given the low barrier to exploitation and the availability of a public PoC, threat actors are likely to continue targeting this vulnerability,” the cybersecurity firm notes.

Organizations and end-users are advised to update to MagicINFO 9 Server version 21.1050 or newer as soon as possible.

An all-in-one solution for content, device, and data management, MagicINFO can be used to create and distribute content to an organization’s linked displays, as well as to remotely manage and secure the displays.

Related: Android Update Patches FreeType Vulnerability Exploited as Zero-Day

Related: Google Warns of Samsung Zero-Day Exploited in the Wild

Related: SonicWall Flags Two More Vulnerabilities as Exploited

Related: Commvault Shares IoCs After Zero-Day Attack Hits Azure Environment

Related Content

Vulnerabilities

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Vulnerabilities

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version