CVE-2025-4998 Details
Description
A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A denial-of-service vulnerability has been identified in the H3C Magic R200G router, specifically in versions up to 100R002. The issue arises in the HTTP POST request handler, within the file '/goform/aspForm'. Several functions are affected, including 'Edit_BasicSSID', 'Edit_BasicSSID_5G', 'SetAPWifiorLedInfoById', 'SetMobileAPInfoById', 'Asp_SetTimingtimeWifiAndLed', 'AddMacList', 'EditMacList', 'AddWlanMacList', and 'EditWlanMacList'. The vulnerability is triggered by manipulating the 'param' argument, leading to a resource exhaustion that causes a denial-of-service condition. This vulnerability can be exploited remotely, and a public exploit is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 20, 2025CISA-ADP
Assessed May 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/CH13hh/tmp_store_cc/blob/main/H3C%20Magic%20R200G/1.md | [email protected] | Broken Link |
| https://vuldb.com/?ctiid.309649 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?id.309649 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.563583 | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| H3C Magic R200G | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2025 | New CVE Received | [email protected] |
Volerion