Research published by SRC:INCITE describes multiple attack chains in Samsung MagicINFO 9 Server version 21.1080.0 that can lead to unauthenticated compromise, administrative account creation, and remote code execution. One chain abuses device registration and approval workflows, a URI-based license-check bypass, exposed dangerous functionality, and hard-coded credentials to provision a device-backed FTP account and upload a malicious serialized file such as Default_MO_TREE.BIN into the mofiles directory. When the Spring application restarts, MORepository deserializes the file, giving an attacker code execution; the researcher also noted that hard-coded database credentials could let an attacker directly manipulate the database and create valid FTP accounts.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Although JSP deployment was blocked by file-type logic, the researcher showed the SQL execution primitive could be used to insert JSP as an allowed file type in the database. That restored a path to remote code execution on the server.
The follow-up post revisited SRC-2025-0003 and CVE-2025-54438-related download functionality, concluding that CifsFileDownloadServlet and especially FtpFileDownloadServlet could still be abused for arbitrary file placement. The researcher said this could also be used for authentication bypass by overwriting the server's index.html.
The researcher found that when DailyJob.checkDbValidation later processed the overwritten JSON, attacker-controlled SQL in the check_query field was executed by ServerSetupInfoImpl. This enabled database takeover actions such as creating a new administrative user.
In a follow-up analysis, the researcher described a separate chain on MagicINFO 9 Server 21.1080.0 that turned patched issues into a practical pre-authentication compromise path despite a roughly daily trigger delay. The chain combined SRC-2025-0004 in ResponseUploadActivity with path manipulation in WSServlet to overwrite PostgreSQL_checklist.json used by a scheduled validation task.
The analysis also found hard-coded database credentials that could be used to directly manipulate the database and create valid FTP accounts, creating a local privilege-escalation and attack-enablement risk. This was presented as part of the same MagicINFO 9 Server research into version 21.1080.0.
The researcher showed that unauthenticated endpoints, a URI-based license-check bypass, and in some cases a hidden orgadmin account with default password could be used to provision and approve a device-backed FTP account. An attacker could then upload a malicious serialized file such as Default_MO_TREE.BIN into the mofiles directory and gain code execution when the Spring application restarted and deserialized it.
A security researcher analyzed Samsung MagicINFO 9 Server version 21.1080.0 and found a multi-step path to remote code execution involving device registration, approval, FTP account provisioning, and unsafe Java deserialization. The issues were tracked as SRC-2025-0001 and SRC-2025-0002, alongside analysis of prior fixes for CVE-2025-54455.
Samsung addressed CVE-2025-54438, an unauthenticated directory traversal and authentication bypass flaw in the downloadChangedFiles function of MagicINFO 9 Server, after it was reported through coordinated disclosure. The issue was reported to the vendor on 2025-04-16 and later publicly disclosed as ZDI-25-655.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
srcincite.io
Open sourcesrcincite.io
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.