Target Industry
Indiscriminate, opportunistic targeting.
Overview
A critical vulnerability in Samsung’s MagicINFO Server has been fixed by Samsung. This vulnerability is a path traversal flaw and is tracked as CVE-2025-4632 (base score 9.8). It has a prove of concept (PoC) and is being actively exploited in the wild. There have been instances where the exploit was used to deploy the Mirai botnet.
Impact
The impact of CVE-2025-4632 is high due to its potential to allow unauthenticated threat actors to gain system-level privileges, leading to remote code execution and server compromise. The Mirai botnet has been seen to be deployed after the vulnerability had been exploited.
Affected Products
Samsung’s MagicINFO Server: version 8 to version 9 prior to 21.1052.
Exploitation
The vulnerability was actively exploited in the wild shortly after a PoC was released in April 2025. Threat actors craft malicious requests that include specially crafted file paths. These paths can traverse directories and access locations outside the intended directory structure. They then write files to arbitrary locations on the server. This can include scripts or executables that the server will run. After the malicious files are in place, they can be executed by the server, leading to unauthorised actions such as deploying malware.
Indicators of Compromise
Indicators of Compromise (IoCs) for the CVE-2025-4632 vulnerability in Samsung’s MagicINFO 9 Server are:
- Unusual Network Traffic: Unexpected outbound traffic, especially to known command-and-control (C2) servers linked to the Mirai botnet
- Unauthorised File Changes: Presence of unfamiliar files or unexpected modifications in system directories
- System Performance Issues: Unusual slowdowns or crashes indicating potential malicious activity
- Suspicious Log Entries: Unauthorised access attempts or execution of unknown scripts in system logs
- Abnormal Device Behaviour: Unexpected reboots or configuration changes in connected devices.
For the IoCs of the Mirai botnet, please refer to the ANY RUN website.
Containment, Mitigations & Remediations
To mitigate the CVE-2025-4632 vulnerability and the Mirai botnet, it is highly recommended to:
CVE-2025-4632:
- Apply Patches: Ensure you have installed the latest security updates provided by Samsung for MagicINFO
- Network Segmentation: Isolate critical systems from less secure networks to prevent lateral movement of threats
- Regular Monitoring: Continuously monitor system logs and network traffic for unusual activity.
Mirai Botnet:
- Change Default Credentials: Update default passwords on IoT devices to strong, unique passwords
- Firmware Updates: Regularly update the firmware of IoT devices to patch known vulnerabilities
- Network Security: Implement firewalls and intrusion detection systems to monitor and block malicious traffic.
Threat Landscape
There was another path traversal flaw (CVE-2024-7399, base score 7.5) in the same product that was patched by Samsung in August 2024. This patch was intended to address and prevent unauthorised access to restricted directories. However, the patch for CVE-2024-7399 was found to be insufficient, leading to the discovery of CVE-2025-4632.
Threat Group
At the time of writing, there is no specific threat group identified as responsible for CVE-2025-4632 or the Mirai botnet attack. Since the publication of the PoC for the vulnerability and source code for Mirai botnet is published online, it has allowed various cybercriminal groups to exploit them.
Further Information













