CVE Feed

    Dashboard / CVE / CVE-2025-29296

    CVE-2025-29296

    H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device.

    Published:Aug 4, 2026
    Last Modified:Aug 5, 2026
    EPS:Aug 4, 2026
    EPSS Score:0.0224
    CVSS Score:9.8

    Affected Products

    Vendor
    H3c
    Product
    Magic Be18000
    Vendor
    H3c
    Product
    Magic Ne36 Pro
    Vendor
    H3c
    Product
    Magic Nx15
    Vendor
    H3c
    Product
    Magic Nx30 Pro
    Vendor
    H3c
    Product
    Magic Nx400
    Vendor
    H3c
    Product
    Magic R100
    Vendor
    H3c
    Product
    Magic R3010

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High