Metrics
Affected Vendors & Products
Tue, 25 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Mar 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | H3C Magic BE18000 HTTP POST Request networkSetup command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-25T03:00:09.183Z
Updated: 2025-03-25T13:58:49.561Z
Reserved: 2025-03-24T12:59:28.444Z
Link: CVE-2025-2729

Updated: 2025-03-25T13:56:37.203Z

Status : Received
Published: 2025-03-25T03:15:16.800
Modified: 2025-03-25T03:15:16.800
Link: CVE-2025-2729

No data.