CVE-2025-3544
Last modified
CVE-2025-3544 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getCapabilityWeb of the component HTTP POST Request Handler. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getCapabilityWeb of the component HTTP POST Request Handler. The manipulation leads to command injection. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
Metrics
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-3544?
How severe is CVE-2025-3544?
How do I fix CVE-2025-3544?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-35431CISA Thorium does not escape user controlled strings used in…5.4
- CVE-2025-35432CISA Thorium does not rate limit requests to send account ve…7.5
- CVE-2025-35433CISA Thorium does not properly invalidate previously used to…8.8
- CVE-2025-35434CISA Thorium does not validate TLS certificates when connect…9.8
- CVE-2025-35435CISA Thorium accepts a stream split size of zero then divide…5.3
- CVE-2025-35436CISA Thorium uses '.unwrap()' to handle errors related to ac…7.5
- CVE-2025-3545A vulnerability was found in H3C Magic NX15, Magic NX30 Pro,…8.6
- CVE-2025-35451PTZOptics and possibly other ValueHD-based pan-tilt-zoom cam…9.8
- CVE-2025-35452PTZOptics and possibly other ValueHD-based pan-tilt-zoom cam…9.8
- CVE-2025-3546A vulnerability was found in H3C Magic NX15, Magic NX30 Pro,…8.6
- CVE-2025-3547A vulnerability classified as critical was found in frdel Ag…6.3
- CVE-2025-35471conda-forge openssl-feedstock before 066e83c (2024-05-20), o…7.8
Are you affected by CVE-2025-3544?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
