Top.Mail.Ru
Хакеры-атаковали-платформу-samsung-magicinfo
Хакеры атаковали платформу Samsung MagicINFO

Hackers have attacked the Samsung MagicINFO platform.

08.05.2025

A critical vulnerability in the Samsung MagicINFO 9 Server platform, discovered in August 2024, has begun to be actively exploited by hackers following the publication of the exploit code, researchers from Arctic Wolf reported.

The vulnerability, identified as CVE-2024−7399, allows attackers to upload malicious files to the server without authorization, gaining full control over the system. This is particularly dangerous as MagicINFO manages screens in stores, airports, and offices.

The issue stems from insufficient file upload verification: the server does not filter file names and extensions, allowing hackers to place malicious JSP files (JavaServer Pages) and execute arbitrary commands. As a result, devices may become part of the Mirai botnet, used for cyberattacks. The exploit has already been observed in attacks.

Samsung has patched the vulnerability in version 21.1050, and the company strongly recommends updating the servers. Arctic Wolf advises organizations to limit internet access to servers and enhance monitoring. The vulnerability has a CVSS rating of 8.8.

Leave a Reply

Your email address will not be published.

loader-image
Ashgabat
,
temperature icon
Humidity
Pressure
Wind
Wind Gust Wind Gust:
Clouds Clouds:
Visibility Visibility:
Sunrise Sunrise:
Sunset Sunset:
Матч-между-ПСЖ-и-Интером-войдет-в-историю
Previous Story

The match between PSG and Inter will go down in history.

Названы-пять-самых-популярных-брендов-настольных-компьютеров-начала-2025-года
Next Story

The five most popular desktop computer brands at the beginning of 2025 have been named.

Latest from Technology

Go toTop