CVE-2025-2730

CVSS 2.0 Score 7.7 of 10 (high)

Details

Published Mar 25, 2025
Updated: Apr 11, 2025
CWE ID 77
CWE ID 74

Summary

CVE-2025-2730 is a newly disclosed critical vulnerability affecting H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 devices up to V100R014. The issue lies within an unknown function of the /api/wizard/getssidname component in the HTTP POST Request Handler. This vulnerability allows for command injection, which can only be exploited within the local network. The exploit has been made public, increasing the threat of potential attacks. It is strongly advised to upgrade the affected components as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Magic NX30 Pro
  • Magic R3010
  • Magic Nx400
  • Magic BE18000

Affected Vendors

  • New H3C Technologies Co. Ltd.