CVE-2025-2732
CVSS 2.0 Score 7.7 of 10 (high)
Details
Summary
CVE-2025-2732 is a critical vulnerability affecting H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 devices up to V100R014. The issue lies within the file /api/wizard/getWifiNeighbour of the HTTP POST Request Handler component, which is yet to be identified. This vulnerability enables command injection, allowing an attacker to manipulate the system when initiated from the local network. The exploit has been made public, increasing the risk of potential attacks. Upgrading the affected component is strongly recommended to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Magic NX30 Pro
- Magic R3010
- Magic Nx400
- Magic BE18000
Affected Vendors
- New H3C Technologies Co. Ltd.