CVE-2025-3544: H3C Magic BE18000 HTTP POST Request getCapabilityWeb FCGI_CheckStringIfContainsSemicolon command injection
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects the function FCGICheckStringIfContainsSemicolon of the file /api/wizard/getCapabilityWeb of the component HTTP POST Request Handler. The manipulation leads to command injection. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3544?
CVE-2025-3544 is classified as a critical vulnerability affecting multiple H3C products.
How do I fix CVE-2025-3544?
To fix CVE-2025-3544, update your H3C device to the latest version beyond V100R014.
What products are affected by CVE-2025-3544?
CVE-2025-3544 affects H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 up to V100R014.
What component is vulnerable in CVE-2025-3544?
The vulnerability in CVE-2025-3544 affects the FCGI_CheckStringIfContainsSemicolon function in the /api/wizard/getCapabilityWeb file.
What type of vulnerability is CVE-2025-3544?
CVE-2025-3544 is a critical vulnerability related to HTTP POST request handling.