Target Industry

Indiscriminate, opportunistic targeting.

Overview

A critical vulnerability in Samsung’s MagicINFO Server has been fixed by Samsung. This vulnerability is a path traversal flaw and is tracked as CVE-2025-4632 (base score 9.8). It has a prove of concept (PoC) and is being actively exploited in the wild. There have been instances where the exploit was used to deploy the Mirai botnet. 

Impact

The impact of CVE-2025-4632 is high due to its potential to allow unauthenticated threat actors to gain system-level privileges, leading to remote code execution and server compromise. The Mirai botnet has been seen to be deployed after the vulnerability had been exploited.  

Affected Products

Samsung’s MagicINFO Server: version 8 to version 9 prior to 21.1052. 

Exploitation

The vulnerability was actively exploited in the wild shortly after a PoC was released in April 2025. Threat actors craft malicious requests that include specially crafted file paths. These paths can traverse directories and access locations outside the intended directory structure. They then write files to arbitrary locations on the server. This can include scripts or executables that the server will run. After the malicious files are in place, they can be executed by the server, leading to unauthorised actions such as deploying malware. 

Indicators of Compromise

Indicators of Compromise (IoCs) for the CVE-2025-4632 vulnerability in Samsung’s MagicINFO 9 Server are: 

  • Unusual Network Traffic: Unexpected outbound traffic, especially to known command-and-control (C2) servers linked to the Mirai botnet 
  • Unauthorised File Changes: Presence of unfamiliar files or unexpected modifications in system directories 
  • System Performance Issues: Unusual slowdowns or crashes indicating potential malicious activity 
  • Suspicious Log Entries: Unauthorised access attempts or execution of unknown scripts in system logs 
  • Abnormal Device Behaviour: Unexpected reboots or configuration changes in connected devices. 

For the IoCs of the Mirai botnet, please refer to the ANY RUN website. 

Containment, Mitigations & Remediations

To mitigate the CVE-2025-4632 vulnerability and the Mirai botnet, it is highly recommended to: 

  • CVE-2025-4632: 

  • Apply Patches: Ensure you have installed the latest security updates provided by Samsung for MagicINFO 
  • Network Segmentation: Isolate critical systems from less secure networks to prevent lateral movement of threats 
  • Regular Monitoring: Continuously monitor system logs and network traffic for unusual activity. 
  • Mirai Botnet: 

  • Change Default Credentials: Update default passwords on IoT devices to strong, unique passwords 
  • Firmware Updates: Regularly update the firmware of IoT devices to patch known vulnerabilities 
  • Network Security: Implement firewalls and intrusion detection systems to monitor and block malicious traffic. 

Threat Landscape

There was another path traversal flaw (CVE-2024-7399, base score 7.5) in the same product that was patched by Samsung in August 2024.  This patch was intended to address and prevent unauthorised access to restricted directories. However, the patch for CVE-2024-7399 was found to be insufficient, leading to the discovery of CVE-2025-4632. 

Threat Group

At the time of writing, there is no specific threat group identified as responsible for CVE-2025-4632 or the Mirai botnet attack. Since the publication of the PoC for the vulnerability and source code for Mirai botnet is published online, it has allowed various cybercriminal groups to exploit them. 

Further Information

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content