CVE-2025-2727
CVSS 2.0 Score 7.7 of 10 (high)
Details
Published Mar 25, 2025
Updated: Apr 11, 2025
CWE ID 77
CWE ID 74
Summary
CVE-2025-2727 is a critical vulnerability affecting H3C Magic NX30 Pro up to V100R007. The issue lies in the HTTP POST Request Handler component and an unknown part of the /api/wizard/getNetworkStatus file. An attacker can exploit this vulnerability through command injection, requiring local network access. The exploit has been made public, increasing the risk of attacks. It is strongly advised to upgrade the affected component to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Magic NX30 Pro
Affected Vendors
- New H3C Technologies Co. Ltd.