Command Injection Vulnerability in H3C Magic Devices
CVE-2025-2732
Summary
A security vulnerability exists in several H3C Magic devices that allows an attacker to execute arbitrary commands through improper handling of HTTP POST requests in the /api/wizard/getWifiNeighbour endpoint. This could allow unauthorized remote control, potentially leading to various malicious activities on affected devices. As exposure details have been publicly disclosed, users are urged to assess their environments and apply necessary mitigations.
Affected Version(s)
Magic BE18000 V100R014
Magic NX15 V100R014
Magic NX30 Pro V100R014
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved