CVE-2025-6091: H3C GR-3000AX aspForm UpdateIpv6Params buffer overflow
A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this issue. Because they assess the risk as low, they do not have immediate plans for remediation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6091?
CVE-2025-6091 has been classified as critical due to its potential for exploiting a buffer overflow.
How do I fix CVE-2025-6091?
To mitigate CVE-2025-6091, you should apply the latest firmware updates provided by H3C for the GR-3000AX.
What type of vulnerability is CVE-2025-6091?
CVE-2025-6091 is a buffer overflow vulnerability found in the UpdateWanParamsMulti and UpdateIpv6Params functions.
What devices are affected by CVE-2025-6091?
CVE-2025-6091 specifically affects H3C GR-3000AX routers.
Can CVE-2025-6091 be exploited remotely?
Yes, CVE-2025-6091 can be exploited remotely if the vulnerable function is accessible.