Command Injection Vulnerability in H3C Magic Products
CVE-2025-3544
8HIGH
What is CVE-2025-3544?
A command injection vulnerability exists within the HTTP POST Request Handler of H3C Magic products, specifically affecting the FCGI_CheckStringIfContainsSemicolon function. This issue enables an attacker with local network access to potentially execute arbitrary commands through specially crafted HTTP requests directed to the /api/wizard/getCapabilityWeb endpoint. Given its public disclosure, it is crucial to promptly apply available upgrades to mitigate associated risks.