CVE-2025-2732: H3C Magic BE18000 HTTP POST Request getWifiNeighbour command injection
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
H3C Magic NX15to a version that resolves this vulnerability.Fixed in V100R014 - Upgrade
Upgrade
H3C Magic NX30 Proto a version that resolves this vulnerability.Fixed in V100R014 - Upgrade
Upgrade
H3C Magic NX400to a version that resolves this vulnerability.Fixed in V100R014 - Upgrade
Upgrade
H3C Magic R3010to a version that resolves this vulnerability.Fixed in V100R014 - Upgrade
Upgrade
H3C Magic BE18000to a version that resolves this vulnerability.Fixed in V100R014 - Compensating control
Since the attack needs to be initiated within the local network, restrict access to the affected HTTP POST Request Handler endpoint (/api/wizard/getWifiNeighbour) to trusted/internal sources only (e.g., via network ACLs/firewall rules).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2732?
CVE-2025-2732 has been rated as critical.
Which devices are affected by CVE-2025-2732?
CVE-2025-2732 affects H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 up to V100R014.
How do I fix CVE-2025-2732?
To fix CVE-2025-2732, you should upgrade the firmware of the affected devices to a version later than V100R014.
What type of vulnerability is CVE-2025-2732?
CVE-2025-2732 is a vulnerability in the HTTP POST Request handling related to the /api/wizard/getWifiNeighbour functionality.
Is there a workaround for CVE-2025-2732?
Currently, it is recommended to apply the firmware update as there are no documented workarounds for CVE-2025-2732.