Metrics
Affected Vendors & Products
Tue, 25 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | H3C Magic BE18000 HTTP POST Request getDualbandSync command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-25T03:31:04.477Z
Updated: 2025-03-25T13:42:47.280Z
Reserved: 2025-03-24T12:59:34.140Z
Link: CVE-2025-2731

Updated: 2025-03-25T13:42:37.530Z

Status : Received
Published: 2025-03-25T04:15:18.943
Modified: 2025-03-25T14:15:31.170
Link: CVE-2025-2731

No data.