CVE-2025-4446: H3C GR-5400AX aspForm Edit_List_SSID buffer overflow
Published May 9, 2025
·Updated
A vulnerability has been found in H3C GR-5400AX up to 100R008 and classified as critical. This vulnerability affects the function EditListSSID of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack needs to be approached within the local network.
Affected Software
1 affected component
H3C GR-5400AX<=100R008
Event History
May 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Mar 8, 57422
Event
via FIRST·12:35 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-4446?
CVE-2025-4446 is classified as a critical vulnerability.
2
What software is affected by CVE-2025-4446?
CVE-2025-4446 affects the H3C GR-5400AX with versions up to 100R008.
3
How do I fix CVE-2025-4446?
To fix CVE-2025-4446, upgrade the H3C GR-5400AX to a version beyond 100R008.
4
What type of vulnerability is CVE-2025-4446?
CVE-2025-4446 is a buffer overflow vulnerability.
5
How is CVE-2025-4446 exploited?
CVE-2025-4446 can be exploited by manipulating the argument param in the Edit_List_SSID function.