CVE-2025-14015: H3C Magic B0 aspForm EditWlanMacList buffer overflow
A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14015?
The severity of CVE-2025-14015 is considered high due to the potential for remote exploitation leading to a buffer overflow.
How do I fix CVE-2025-14015?
To fix CVE-2025-14015, update your H3C Magic B0 device to a version beyond 100R002 that addresses this vulnerability.
What products are affected by CVE-2025-14015?
CVE-2025-14015 affects H3C Magic B0 devices up to and including version 100R002.
Can CVE-2025-14015 be exploited remotely?
Yes, CVE-2025-14015 can be remotely exploited, making it critical for users to apply mitigations.
What type of vulnerability is CVE-2025-14015?
CVE-2025-14015 is classified as a buffer overflow vulnerability, specifically affecting the EditWlanMacList function.