CVE-2025-3546 Details
Description
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.
A command injection vulnerability has been identified in several H3C Magic home router models, including the NX15, NX30 Pro, NX400, R3010, and BE18000, all through specific versions. The vulnerability resides in the HTTP POST request handler, specifically within the 'FCGI_CheckStringIfContainsSemicolon' function, where improper input validation allows for command injection. This issue can only be exploited from within the local network.
Users are advised to upgrade to the latest firmware versions available on the H3C website. For specific upgrade instructions, refer to the H3C software download page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/isstabber/154661f329e4ae6bfe15dcdc0b932ff3 | [email protected] | Broken Link |
| https://vuldb.com/?ctiid.304585 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.304585 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.524745 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product/ | [email protected] | Product |
| https://zhiliao.h3c.com/theme/details/229784 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-74 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| h3c magic nx15 firmware | <= 100r014 |
CPE
Remediation
| |
| h3c magic nx15 | All versions |
CPE
Remediation
| |
| h3c magic nx30 pro firmware | <= 100r014 |
CPE
Remediation
| |
| h3c magic nx30 pro | All versions |
CPE
Remediation
| |
| h3c magic nx400 firmware | <= 100r014 |
CPE
Remediation
| |
| h3c magic nx400 | All versions |
CPE
Remediation
| |
| h3c magic r3010 firmware | <= 100r014 |
CPE
Remediation
| |
| h3c magic r3010 | All versions |
CPE
Remediation
| |
| h3c magic be18000 firmware | <= 100r014 |
CPE
Remediation
| |
| h3c magic be18000 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2026 | Reanalysis | [email protected] |
| Feb 10, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2025 | New CVE Received | [email protected] |