Metrics
Affected Vendors & Products
Tue, 25 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Mar 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | H3C Magic BE18000 HTTP POST Request auth command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-25T02:00:09.925Z
Updated: 2025-03-25T13:22:41.747Z
Reserved: 2025-03-24T12:59:17.247Z
Link: CVE-2025-2725

Updated: 2025-03-25T13:22:19.194Z

Status : Received
Published: 2025-03-25T03:15:16.097
Modified: 2025-03-25T14:15:30.710
Link: CVE-2025-2725

No data.