References https://nvd.nist.gov/vuln/detail/CVE-2025-4632 https://www.cve.org/CVERecord?id=CVE-2025-4632 https://www.tenable.com/cve/CVE-2025-4632 https://ssd-disclosure.com/ssd-advisory-samsung-magicinfo-unauthenticated-rce/ https://www.huntress.com/blog/post-exploitation-activities-observed-from-samsung-magicinfo-9-server-flaw https://thehackernews.com/2025/05/samsung-patches-cve-2025-4632-used-to.html https://security.samsungtv.com/securityUpdates#SVP-MAY-2025 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-4632.yaml https://www.sentinelone.com/vulnerability-database/cve-2025-4632/ https://www.darkreading.com/endpoint-security/attackers-target-samsung-magicinfo-server-bug
Related VulnerabilitiesMagicINFO SWUpdateFileUploader 文件上传漏洞PoCCVE-2024-7399: Samsung MagicINFO 9 Server 21.1050.0 - Remote Code ExecutionPoCCVE-2025-4632: Samsung MagicINFO 9 Server - File Upload & Remote Code Execution(CVE-2025-4632) Samsung MagicINFO 9 Server目录限制不足漏洞