Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
id: CVE-2025-4632
info:
name: Samsung MagicINFO 9 Server - File Upload & Remote Code Execution
...