Command Injection Vulnerability in H3C Magic NX30 Pro and NX400 by H3C Technologies Co., Ltd.
CVE-2025-2728
What is CVE-2025-2728?
A command injection vulnerability has been identified in the H3C Magic NX30 Pro and Magic NX400 devices impacting the /api/wizard/getNetworkConf endpoint. This flaw allows unauthorized remote attackers to execute arbitrary commands on these devices. Despite prior notification to H3C Technologies Co., Ltd., the response to this security issue was not forthcoming, leaving users at risk of compromise. It is essential for organizations utilizing these products to assess their exposure and take appropriate measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Magic NX30 Pro V100R014
Magic NX400 V100R014
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved