A critical vulnerability (CVE-2025-4632) in Samsung's MagicINFO 9 Server is being actively exploited by attackers to gain system-level access and deploy malicious payloads. This path traversal flaw allows attackers to write arbitrary files with system-level privileges. Signs of compromise have been observed in real-world environments, including attempts to deploy Mirai malware. Organizations using MagicINFO are strongly urged to act quickly and apply patches immediately.