CVE-2025-2726: H3C Magic BE18000 HTTP POST Request esps command injection
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command injection. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2726?
CVE-2025-2726 has been classified as a critical vulnerability.
How does CVE-2025-2726 affect H3C devices?
CVE-2025-2726 affects the file /api/esps within the HTTP POST Request Handler on specific H3C models.
What versions of H3C products are vulnerable to CVE-2025-2726?
H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 up to V100R014 are all affected by CVE-2025-2726.
How do I fix CVE-2025-2726?
To remediate CVE-2025-2726, upgrade all affected H3C devices to a version beyond V100R014.
Can CVE-2025-2726 lead to unauthorized access?
Yes, CVE-2025-2726 may allow attackers to exploit vulnerabilities and gain unauthorized access to the affected H3C devices.