CVE-2025-5156: H3C GR-5400AX aspForm EditWlanMacList buffer overflow
A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical. Affected by this issue is the function EditWlanMacList of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5156?
CVE-2025-5156 is classified as a critical vulnerability.
What is the impact of CVE-2025-5156?
CVE-2025-5156 can lead to a buffer overflow due to manipulation of the parameter in the EditWlanMacList function.
How do I fix CVE-2025-5156?
To fix CVE-2025-5156, update the H3C GR-5400AX to a version newer than 100R008.
Is CVE-2025-5156 exploitable remotely?
Yes, CVE-2025-5156 can be exploited remotely.
Which devices are affected by CVE-2025-5156?
CVE-2025-5156 affects the H3C GR-5400AX devices up to version 100R008.