CVE-2025-60262: Critical severity H3C M102G HM1A0V200R010 vulnerability

Published Jan 6, 2026
·
Updated

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.

Affected Software

7 affected components
H3C M102G HM1A0V200R010
H3C BA1500L SWBA1A0V100R006
vsftpd
All of the following
H3C Mc102-g Firmware=hm1a0v200r010
H3C Mc102-g
All of the following
H3C Magic Ba1500l Firmware=swba1a0v100r006
H3C Magic Ba1500l

Event History

Jan 6, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-60262?

CVE-2025-60262 has a moderate severity due to potential unauthorized file manipulation over FTP.

2

How do I fix CVE-2025-60262?

To fix CVE-2025-60262, reconfigure the vsftpd settings to restrict anonymous uploads and ensure proper file ownership.

3

What products are affected by CVE-2025-60262?

CVE-2025-60262 affects the H3C M102G HM1A0V200R010 wireless controller and the H3C BA1500L SWBA1A0V100R006 wireless access point.

4

What type of vulnerability is CVE-2025-60262?

CVE-2025-60262 is a misconfiguration vulnerability related to anonymous FTP uploads.

5

How does CVE-2025-60262 impact my network security?

CVE-2025-60262 can pose a risk by allowing unauthorized users to upload files that could compromise network security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203