Vulnerability
Published 2026-09-24
Verified 2026-09-27

Samsung MagicINFO 9 CVE-2025-4632 (CVSS 9.8, CISA KEV): path traversal → SYSTEM write — Huntress sees on-host Monero miner build

Huntress (24 September 2026) reports an early-September 2026 intrusion that began with exploitation of Samsung MagicINFO 9 Server CVE-2025-4632 (path traversal / arbitrary file write as SYSTEM; incomplete fix lineage from CVE-2024-7399). After access via the Tomcat-hosted MagicINFO service, the actor repeatedly tried to install AnyDesk (source IP 194.87.89.30), created a local admin, disabled Microsoft Defender, then compiled a Silent XMR Miner–based Monero miner on the endpoint (noisy csc/gcc/tcc/donut telemetry) and pointed it at auto.c3pool.org:19999. NVD / Samsung PSIRT: CVSS 3.1 9.8 CRITICAL (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); affected MagicINFO 9 Server before 21.1052; fixed May 2025. CISA KEV entry (added 2025-05-22; catalog still lists). Primary: Huntress; CVE metadata: NVD; vendor notes via KEV → security.samsungtv.com SVP-MAY-2025.

Product
Samsung MagicINFO 9 Server (digital signage / content management; Tomcat)
Versions
Affected: MagicINFO 9 Server before 21.1052 (NVD/Samsung). Fixed May 2025 in 21.1052+. CVE-2024-7399 was an earlier related incomplete fix (Huntress).
CVSS
(CVSS 3.1 CRITICAL, Samsung PSIRT / NVD)
Exploited in Australia?
unknown
Patch to
Upgrade MagicINFO 9 Server to 21.1052 or later; remove internet exposure of signage management. Hunt IoCs: AnyDesk drops from 194.87.89.30, Silent XMR Miner Builder / compiler burst (csc.exe, gcc, tcc, donut), miner to auto.c3pool.org:19999, Defender tampering, unexpected local admin. CISA KEV: apply vendor mitigations or discontinue if unavailable.

Primary: Huntress — The Not So Silent Miner (MagicINFO → on-host Monero build) (24 Sep 2026) · Vendor: Samsung TV / MagicINFO security updates (SVP-MAY-2025; CISA KEV notes) · CVE: CVE-2025-4632, CVE-2024-7399 · NVD — CVE-2025-4632 (CVSS 9.8; MagicINFO 9 Server < 21.1052); also CISA KEV

vulnerabilities network