CVE-2024-7399

HIGH KEV NUCLEI

Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2024-7399 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 24, 2026. EIP tracks 2 public exploits from researchers including davidxbors, Michael Heinzl, SSD Secure Disclosure, including a Metasploit module exploits/windows/http/magicinfo_traversal. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a Python-based exploit for CVE-2024-7399, targeting a path traversal vulnerability in Samsung MagicInfo's SWUpdateFileUploader servlet. The exploit allows arbitrary file upload and remote code execution (RCE) via JSP payloads.

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

Exploits (2)

nomisec WORKING POC
by davidxbors · remote
https://github.com/davidxbors/CVE-2024-7399-POC

This repository contains a Python-based exploit for CVE-2024-7399, targeting a path traversal vulnerability in Samsung MagicInfo's SWUpdateFileUploader servlet. The exploit allows arbitrary file upload and remote code execution (RCE) via JSP payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Samsung MagicInfo (version not specified)
No auth needed
Prerequisites: Network access to the target server · Samsung MagicInfo with vulnerable SWUpdateFileUploader servlet
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Michael Heinzl, SSD Secure Disclosure · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/magicinfo_traversal.rb

This Metasploit module exploits CVE-2024-7399, a path traversal vulnerability in Samsung MagicINFO 9 Server, allowing unauthenticated remote code execution via JSP shell upload. The exploit targets the SWUpdateFileUploader servlet and executes payloads in the context of NT AUTHORITY\SYSTEM.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Samsung MagicINFO 9 Server <= 21.1050.0
No auth needed
Prerequisites: Network access to TCP ports 7001 (HTTP) or 7002 (HTTPS) · Target running vulnerable version of Samsung MagicINFO
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Samsung MagicINFO 9 Server 21.1050.0 - Remote Code Execution
HIGHVERIFIEDby iamnoooob,pdresearch
Shodan: Server: MagicInfo Premium Server

Scores

CVSS v3 8.8
EPSS 0.7443
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-04-24
VulnCheck KEV 2025-05-05
ENISA EUVD EUVD-2024-48330
CWE
CWE-22 CWE-434
Status published
Products (2)
samsung/magicinfo_9_server < 21.1050
Samsung Electronics/MagicINFO 9 Server < 21.1050
Published Aug 12, 2024
KEV Added Apr 24, 2026
Tracked Since Feb 18, 2026