CVE-2025-2727

CVSS 2.0 Score 7.7 of 10 (high)

Details

Published Mar 25, 2025
Updated: Apr 11, 2025
CWE ID 77
CWE ID 74

Summary

CVE-2025-2727 is a critical vulnerability affecting H3C Magic NX30 Pro up to V100R007. The issue lies in the HTTP POST Request Handler component and an unknown part of the /api/wizard/getNetworkStatus file. An attacker can exploit this vulnerability through command injection, requiring local network access. The exploit has been made public, increasing the risk of attacks. It is strongly advised to upgrade the affected component to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Magic NX30 Pro

Affected Vendors

  • New H3C Technologies Co. Ltd.