Multiple Command Injection Vulnerabilities in H3C Network Devices
CVE-2025-29296
9.8CRITICAL
Key Information:
- Vendor
H3C
- Vendor
- CVE Published:
- 4 August 2026
What is CVE-2025-29296?
Multiple command injection vulnerabilities exist in several H3C network devices, specifically within the /api/esps request handler. These vulnerabilities affect various functions related to VLAN management, URL filtering, system version control, and network time protocol settings. By exploiting these flaws, an attacker can manipulate user-controlled request parameters, which are incorporated into shell commands without proper validation. This can lead to arbitrary command execution with root privileges, allowing complete control over the compromised device.