CVE-2025-3545: H3C Magic BE18000 HTTP POST Request setLanguage FCGI_CheckStringIfContainsSemicolon command injection
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is the function FCGICheckStringIfContainsSemicolon of the file /api/wizard/setLanguage of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3545?
CVE-2025-3545 is classified as a critical vulnerability.
What products are affected by CVE-2025-3545?
CVE-2025-3545 affects H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010, and Magic BE18000 up to version V100R014.
How do I fix CVE-2025-3545?
To fix CVE-2025-3545, upgrade the affected H3C devices to the latest version beyond V100R014.
What component is vulnerable in CVE-2025-3545?
The vulnerable component in CVE-2025-3545 is the function FCGI_CheckStringIfContainsSemicolon in the /api/wizard/setLanguage file.
Can CVE-2025-3545 lead to serious security breaches?
Yes, due to its critical classification, CVE-2025-3545 can lead to serious security breaches if exploited.