CVE-2025-2728

CVSS 3.1 Score 8.5 of 10 (high)

Details

Published Mar 25, 2025
Updated: Apr 11, 2025
CWE ID 89

Summary

CVE-2025-2728 is a critical vulnerability affecting H3C Magic NX30 Pro and Magic NX400 devices up to V100R014. The issue lies within the unknown code of the /api/wizard/getNetworkConf file and allows for command injection. An attacker must be present in the local network to exploit this vulnerability. It is strongly advised to upgrade the affected component to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share