CVE-2025-2728: H3C Magic NX30 Pro/Magic NX400 getNetworkConf command injection
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs to be approached within the local network. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
H3C Magic NX30 Pro and Magic NX400to a version that resolves this vulnerability.Fixed in V100R014 - Compensating control
Approach/contain the attack within the local network (use network-level restrictions/segmentation so only local network traffic can reach the affected device/API endpoints).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2728?
CVE-2025-2728 is classified as critical due to its potential for remote command injection.
How does CVE-2025-2728 affect H3C Magic NX30 Pro and Magic NX400?
CVE-2025-2728 affects the /api/wizard/getNetworkConf file, allowing for remote command injection.
Who is affected by CVE-2025-2728?
CVE-2025-2728 affects users of H3C Magic NX30 Pro and Magic NX400 devices running software versions up to V100R014.
What can be exploited in CVE-2025-2728?
CVE-2025-2728 can be exploited to manipulate unknown code leading to command injection.
What are the potential risks of CVE-2025-2728?
The risks of CVE-2025-2728 include unauthorized access and execution of arbitrary commands on affected devices.