Buffer Overflow in H3C GR-3000AX Router
CVE-2025-6091
8.7HIGH
What is CVE-2025-6091?
A buffer overflow vulnerability exists in the H3C GR-3000AX router, specifically within the UpdateWanParamsMulti and UpdateIpv6Params functions found in the /routing/goform/aspForm file. This flaw allows an attacker to manipulate the 'param' argument, potentially leading to unauthorized access and execution of arbitrary code. The vulnerability can be exploited remotely, posing a risk to users. Although the vendor acknowledges the issue, they currently assess it as low risk without immediate remediation plans.
Affected Version(s)
GR-3000AX V100R007L50