Metrics
Affected Vendors & Products
Tue, 25 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Mar 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | H3C Magic NX30 Pro HTTP POST Request getNetworkStatus command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-25T02:31:03.932Z
Updated: 2025-03-25T13:59:08.375Z
Reserved: 2025-03-24T12:59:23.068Z
Link: CVE-2025-2727

Updated: 2025-03-25T13:55:56.779Z

Status : Received
Published: 2025-03-25T03:15:16.450
Modified: 2025-03-25T03:15:16.450
Link: CVE-2025-2727

No data.