CVE-2025-57577: High severity H3C Device R365 vulnerability
An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a case of misconfiguration if an administrator deliberately ignored the prompts, which is outside the scope of CVE definitions."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57577?
CVE-2025-57577 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-57577?
To fix CVE-2025-57577, change the default password of the H3C Device R365 immediately and ensure strong password policies are enforced.
Who is affected by CVE-2025-57577?
CVE-2025-57577 affects users of the H3C Device R365 running the R365V300R004 firmware version.
What type of vulnerability is CVE-2025-57577?
CVE-2025-57577 is a remote code execution vulnerability that can be exploited through the use of default credentials.
What are the potential impacts of CVE-2025-57577?
The potential impacts of CVE-2025-57577 include unauthorized access and control over the H3C Device R365 system by attackers.