CVE-2025-29296
Last modified
CVE-2025-29296 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15).
Description
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2025-29296?
How severe is CVE-2025-29296?
How do I fix CVE-2025-29296?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-2928SQL Injection affecting the Archiver role.7.2
- CVE-2025-29280Stored cross-site scripting vulnerability exists in PerfreeB…4.8
- CVE-2025-29281In PerfreeBlog version 4.0.11, regular users can exploit the…8.8
- CVE-2025-29287An arbitrary file upload vulnerability in the ueditor compon…9.8
- CVE-2025-2929The Order Delivery Date WordPress plugin before 12.4.0 does …7.1
- CVE-2025-29294Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2025-29306An issue in FoxCMS v.1.2.5 allows a remote attacker to execu…9.8
- CVE-2025-29310An issue in onos v2.7.0 allows attackers to trigger a packet…9.8
- CVE-2025-29311Limited secret space in LLDP packets used in onos v2.7.0 all…7.5
- CVE-2025-29312An issue in onos v2.7.0 allows attackers to trigger unexpect…9.1
- CVE-2025-29313Use of incorrectly resolved name or reference in OpenDayligh…7.5
- CVE-2025-29314Insecure Shiro cookie configurations in OpenDaylight Service…8.1
Are you affected by CVE-2025-29296?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
