CVE-2025-3542: H3C Magic NX15/Magic NX400/Magic R3010 HTTP POST Request getsyncpppoecfg FCGI_WizardProtoProcess command injection
A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGIWizardProtoProcess of the file /api/wizard/getsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3542?
CVE-2025-3542 is classified as a critical vulnerability.
Which products are affected by CVE-2025-3542?
CVE-2025-3542 affects H3C Magic NX15, Magic NX400, and Magic R3010 up to version V100R014.
What component is vulnerable in CVE-2025-3542?
The vulnerability primarily affects the HTTP POST Request Handler component in the function FCGI_WizardProtoProcess.
How can I mitigate the risks associated with CVE-2025-3542?
To mitigate CVE-2025-3542, consider updating to a version of the affected product that is higher than V100R014.
What impact can CVE-2025-3542 have on my system?
CVE-2025-3542 could lead to unauthorized manipulation of configuration settings via the exposed API.