- Description
- A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used.
- Source
- cna@vuldb.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 8.6
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 8
- Impact score
- 5.9
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Secondary
- Base score
- 7.7
- Impact score
- 10
- Exploitability score
- 5.1
- Vector string
- AV:A/AC:L/Au:S/C:C/I:C/A:C
- cna@vuldb.com
- CWE-74
- Hype score
- Not currently trending
�� CVE-2025-2730 - H3C Magic Series Routers (NX15 - HIGH 🚨 🗓️ Date published 2025-03-25 03:15:16 UTC #H3CMagicSeriesRouters(NX15 #CyberSecurity #InfoSec #Vulnerability #TechNews https://t.co/wP3jLAzzGR
@vulns_space
27 Mar 2025
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-2730 🔴 HIGH (8.7) 🏢 H3C - Magic NX15 🏗️ V100R014 🔗 https://t.co/xLh5PoJt1T 🔗 https://t.co/Bae97OVmFX 🔗 https://t.co/OdyqXZpSgg 🔗 https://t.co/eyEyhp7QYd #CyberCron #VulnAlert #InfoSec https://t.co/Tyi0obYQon
@cybercronai
26 Mar 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
�� CVE-2025-2730 - H3C Magic NX15 - HIGH 🚨 🗓️ Date published 2025-03-25 03:15:16 UTC #H3CMagicNX15 #CyberSecurity #InfoSec #Vulnerability #TechNews https://t.co/BFX6yHkgup
@vulns_space
25 Mar 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-2730: HIGH] Critical vulnerability in H3C Magic products up to V100R014 allows for remote command injection, exposing systems to attacks. Vendor was notified but did not respond.#cybersecurity,#vulnerability https://t.co/SiCyC9CO92 https://t.co/VOwifBNqwS
@CveFindCom
25 Mar 2025
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes