CVE-2024-7399

Samsung MagicINFO 9 Server Path Traversal Vulnerability

9.8
CVSS 3.1
91.9 %
EPSS (current)
2026-04-24
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Samsung / MagicINFO 9 Server

Published: 2024-08-12 · Due (CISA): 2026-05-08

CWE: CWE-22 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2024/CVE-2024-7399.yamlSamsung MagicINFO 9 Server 21.1050.0 - Remote Code Execution–
metasploitexploit/windows/http/magicinfo_traversalexploit/windows/http/magicinfo_traversal2025-04-30

References only — no downloads or instructions.

Sources