CVE-2025-14196: H3C Magic B1 aspForm sub_44de0 buffer overflow
A weakness has been identified in H3C Magic B1 up to 100R004. The affected element is the function sub44de0 of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14196?
CVE-2025-14196 is considered a high-severity vulnerability due to its potential for remote exploitation through buffer overflow.
How do I fix CVE-2025-14196?
To fix CVE-2025-14196, you should upgrade H3C Magic B1 to the latest firmware version beyond 100R004 that addresses this vulnerability.
What devices are affected by CVE-2025-14196?
CVE-2025-14196 affects H3C Magic B1 devices running firmware version up to and including 100R004.
Can CVE-2025-14196 be exploited remotely?
Yes, CVE-2025-14196 can be exploited remotely by manipulating the relevant parameters to trigger a buffer overflow.
What specific function is vulnerable in CVE-2025-14196?
The vulnerability in CVE-2025-14196 is found in the function sub_44de0 located in the /goform/aspForm file.