CVE-2025-8907: H3C M2 NAS Webserver Configuration unnecessary privileges
A vulnerability was found in H3C M2 NAS V100R006. Affected by this vulnerability is an unknown functionality of the component Webserver Configuration. The manipulation leads to execution with unnecessary privileges. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor explains: "[T]he device only has configuration files and does not actually have boa functionality. It is impossible to access or upload files anonymously to the device through boa services". This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8907?
CVE-2025-8907 has been classified as having a high severity due to its ability to allow execution with unnecessary privileges.
How do I fix CVE-2025-8907?
To fix CVE-2025-8907, ensure that you apply the latest security patches released by H3C for the M2 NAS product.
What components are affected by CVE-2025-8907?
CVE-2025-8907 affects the Webserver Configuration component of the H3C M2 NAS.
Can CVE-2025-8907 be exploited remotely?
No, CVE-2025-8907 requires local access for an attack to be executed.
What potential impact does CVE-2025-8907 have on systems?
The impact of CVE-2025-8907 includes unauthorized privilege escalation, which can compromise system security.