CVE-2025-61330: Medium severity H3C Magic-branded devices vulnerability

Published Oct 16, 2025
·
Updated

A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of a hard-coded weak password for the root account in the /etc/shadow configuration or even the absence of any password at all. Some of these devices have the Telnet service enabled by default, or users can choose to enable the Telnet service in other device management interfaces (e.g. /debug.asp or /debugtelnet.asp). In addition, these devices have related interfaces called Virtual Servers, which can map the devices to the public network, posing the risk of remote attacks. Therefore, attackers can obtain the highest root privileges of the devices through the Telnet service using the weak password hardcoded in the firmware (or without a password), and remote attacks are possible.

Affected Software

1 affected component
H3C Magic-branded devices

Event History

Oct 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-61330?

The severity of CVE-2025-61330 is high due to the exploitation risk from a hard-coded weak password.

2

How do I fix CVE-2025-61330?

To fix CVE-2025-61330, replace the hard-coded weak password for the root account with a strong, unique password.

3

Which devices are affected by CVE-2025-61330?

CVE-2025-61330 affects all Magic-branded devices manufactured by H3C.

4

What potential risks does CVE-2025-61330 pose?

CVE-2025-61330 poses risks such as unauthorized access and control over the affected H3C Magic-branded devices.

5

Is there a patch available for CVE-2025-61330?

As of now, check with H3C for any patches or updates addressing CVE-2025-61330.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203