Command Injection Vulnerability in H3C Magic Devices
CVE-2025-2732
8.6HIGH
What is CVE-2025-2732?
A security vulnerability exists in several H3C Magic devices that allows an attacker to execute arbitrary commands through improper handling of HTTP POST requests in the /api/wizard/getWifiNeighbour endpoint. This could allow unauthorized remote control, potentially leading to various malicious activities on affected devices. As exposure details have been publicly disclosed, users are urged to assess their environments and apply necessary mitigations.
Affected Version(s)
Magic BE18000 V100R014
Magic NX15 V100R014
Magic NX30 Pro V100R014
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Qwen (VulDB User)