CVE Feed

    Dashboard / CVE / CVE-2025-60262

    CVE-2025-60262

    An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.

    Published:Jan 6, 2026
    Last Modified:Jan 29, 2026
    EPS:Jan 6, 2026
    EPSS Score:0.00144
    CVSS Score:9.8

    Affected Products

    Vendor
    H3c
    Product
    Ba1500l
    Vendor
    H3c
    Product
    M102g
    Vendor
    H3c
    Product
    Magic Ba1500l
    Vendor
    H3c
    Product
    Magic Ba1500l Firmware
    Vendor
    H3c
    Product
    Mc102-g
    Vendor
    H3c
    Product
    Mc102-g Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High