Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
https://thehackernews.com/2026/04/cisa-adds-4-exploited-flaws-to-kev-sets.html
https://www.securityweek.com/improperly-patched-samsung-magicinfo-vulnerability-exploited-by-botnet/
https://thehackernews.com/2025/05/hackers-exploit-samsung-magicinfo.html