CVE-2025-61330: Medium severity H3C Magic-branded devices vulnerability
A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from Chinese network equipment manufacturer H3C. The vulnerability stems from the use of a hard-coded weak password for the root account in the /etc/shadow configuration or even the absence of any password at all. Some of these devices have the Telnet service enabled by default, or users can choose to enable the Telnet service in other device management interfaces (e.g. /debug.asp or /debugtelnet.asp). In addition, these devices have related interfaces called Virtual Servers, which can map the devices to the public network, posing the risk of remote attacks. Therefore, attackers can obtain the highest root privileges of the devices through the Telnet service using the weak password hardcoded in the firmware (or without a password), and remote attacks are possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61330?
The severity of CVE-2025-61330 is high due to the exploitation risk from a hard-coded weak password.
How do I fix CVE-2025-61330?
To fix CVE-2025-61330, replace the hard-coded weak password for the root account with a strong, unique password.
Which devices are affected by CVE-2025-61330?
CVE-2025-61330 affects all Magic-branded devices manufactured by H3C.
What potential risks does CVE-2025-61330 pose?
CVE-2025-61330 poses risks such as unauthorized access and control over the affected H3C Magic-branded devices.
Is there a patch available for CVE-2025-61330?
As of now, check with H3C for any patches or updates addressing CVE-2025-61330.