Metrics
Affected Vendors & Products
Mon, 14 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 14 Apr 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. | |
Title | H3C Magic BE18000 HTTP POST Request getLanguage FCGI_CheckStringIfContainsSemicolon command injection | |
Weaknesses | CWE-74 CWE-77 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-14T15:54:23.768Z
Reserved: 2025-04-13T12:28:38.864Z
Link: CVE-2025-3546

Updated: 2025-04-14T15:54:17.417Z

Status : Received
Published: 2025-04-14T02:15:13.333
Modified: 2025-04-14T02:15:13.333
Link: CVE-2025-3546

No data.