<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Samsung</title><description>Actively exploited vulnerabilities affecting Samsung products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/samsung.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2024-7399 — Samsung MagicINFO 9 Server Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-7399</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-7399</guid><description>Samsung MagicINFO 9 Server, a digital signage management platform, contains a path traversal flaw that lets unauthenticated or low-privilege attackers write arbitrary files with system-level authority. This is serious because writing files as the system account can enable full server compromise — attackers could plant web shells, overwrite configuration files, or stage further attacks across managed display infrastructure without needing elevated credentials.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>Samsung</category><category>MagicINFO 9 Server</category></item><item><title>CVE-2025-21042 — Samsung Mobile Devices Out-of-Bounds Write Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-21042</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-21042</guid><description>A flaw in Samsung&apos;s libimagecodec.quram.so library allows remote attackers to write data outside intended memory boundaries, potentially enabling arbitrary code execution on affected mobile devices. Because exploitation can be triggered remotely without physical access, a successful attack could give an attacker full control over the device — including access to sensitive data, communications, and corporate resources — making this a serious risk for any organization with Samsung devices in its environment.</description><pubDate>Mon, 10 Nov 2025 00:00:00 GMT</pubDate><category>Samsung</category><category>Mobile Devices</category></item><item><title>CVE-2025-21043 — Samsung Mobile Devices Out-of-Bounds Write Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-21043</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-21043</guid><description>An out-of-bounds write flaw in Samsung&apos;s libimagecodec.quram.so library allows remote attackers to execute arbitrary code on affected Samsung mobile devices without requiring physical access. This is a serious risk because successful exploitation could give attackers full control over a device, potentially exposing corporate email, credentials, sensitive data, and enabling further network compromise — all without user interaction beyond receiving or processing malicious content.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><category>Samsung</category><category>Mobile Devices</category></item><item><title>CVE-2025-4632 — Samsung MagicINFO 9 Server Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-4632</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-4632</guid><description>Samsung MagicINFO 9 Server, a digital signage management platform, contains a path traversal flaw that lets an unauthenticated or remote attacker write arbitrary files with system-level authority. This is severe because writing files as the system account can enable full server compromise — attackers could plant web shells, overwrite configuration files, or establish persistent backdoors — affecting any organization running digital signage infrastructure on this platform.</description><pubDate>Thu, 22 May 2025 00:00:00 GMT</pubDate><category>Samsung</category><category>MagicINFO 9 Server</category></item></channel></rss>