CVE-2025-2726

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Mar 25, 2025
Updated: Apr 11, 2025
CWE ID 89

Summary

CVE-2025-2726 is a critical vulnerability affecting H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 devices up to V100R014. This issue lies within the unknown functionality of the /api/esps component's HTTP POST Request Handler. By manipulating this feature, an attacker can inject commands. Access to the local network is a prerequisite for a successful exploit. The exploit has been disclosed publicly, increasing the risk of attacks. It is strongly advised to upgrade the affected component to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share