CVE-2025-2730: H3C Magic BE18000 HTTP POST Request getssidname command injection
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
H3C Magicto a version that resolves this vulnerability.Fixed in V100R014 - Compensating control
Limit access so exploitation can only be initiated within the local network (e.g., restrict reachability of the vulnerable HTTP POST Request Handler on the device to the local network using network segmentation/ACLs/firewall rules).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2730?
CVE-2025-2730 has been classified as a critical vulnerability.
What components are affected by CVE-2025-2730?
CVE-2025-2730 affects the HTTP POST Request Handler in the /api/wizard/getssidname file.
Which H3C products are impacted by CVE-2025-2730?
H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 are all impacted by CVE-2025-2730.
How do I mitigate CVE-2025-2730?
To mitigate CVE-2025-2730, it is recommended to update the affected H3C products to versions later than V100R014.
What should I do if I am vulnerable to CVE-2025-2730?
If you are vulnerable to CVE-2025-2730, you should immediately apply the security updates provided by H3C.