Description

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

INFO

Published Date :

2025-04-14T01:31:07.222Z

Last Modified :

2025-04-14T15:54:23.768Z

Source :

VulDB
AFFECTED PRODUCTS

The following products are affected by CVE-2025-3546 vulnerability.

Vendors Products
H3c
  • Magic Be18000
  • Magic Be18000 Firmware
  • Magic Nx15
  • Magic Nx15 Firmware
  • Magic Nx30 Pro
  • Magic Nx30 Pro Firmware
  • Magic Nx400
  • Magic Nx400 Firmware
  • Magic R3010
  • Magic R3010 Firmware

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Detailed values of each vector for above chart.
Access Vector
Access Complexity
Authentication
Confidentiality Impact
Integrity Impact
Availability Impact