CVE-2025-63258: Command Injection
A remote command execution (RCE) vulnerability was discovered in all H3C ERG3/ERG5 series routers and XiaoBei series routers, cloud gateways, and wireless access points (versions R0162P07, UAP700-WPT330-E2265, UAP672-WPT330-R2262, UAP662E-WPT330-R2262P03, WAP611-WPT330-R1348-OASIS, WAP662-WPT330-R2262, WAP662H-WPT330-R2262, USG300V2-WPT330-R2129, MSG300-WPT330-R1350, and MSG326-WPT330-R2129). Attackers are able to exploit this vulnerability via injecting crafted commands into the sessionid parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the RCE by blocking or filtering HTTP requests that contain the sessionid parameter with injected crafted command patterns at the network perimeter (e.g., firewall/WAF), until the affected router/AP/gateway firmware is patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63258?
CVE-2025-63258 is classified as a high severity remote command execution vulnerability.
How do I fix CVE-2025-63258?
To mitigate CVE-2025-63258, update the affected H3C routers to the latest firmware version provided by the vendor.
What devices are affected by CVE-2025-63258?
CVE-2025-63258 affects H3C ERG3/ERG5 series routers, XiaoBei series routers, as well as cloud gateways and certain wireless access points.
Can CVE-2025-63258 be exploited remotely?
Yes, CVE-2025-63258 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected devices.
What versions are impacted by CVE-2025-63258?
CVE-2025-63258 impacts specific versions of H3C devices including R0162P07, UAP700-WPT330-E2265, UAP672-WPT330-R2262, among others.