Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-60262 Details

Description

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-276Incorrect Default PermissionsCISA-ADP

Affected Products

ProductVersions
h3c mc102-g firmware
hm1a0v200r010

CPE

  • cpe:2.3:o:h3c:mc102-g_firmware:hm1a0v200r010:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
h3c mc102-g
All versions

CPE

  • cpe:2.3:h:h3c:mc102-g:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
h3c magic ba1500l firmware
swba1a0v100r006

CPE

  • cpe:2.3:o:h3c:magic_ba1500l_firmware:swba1a0v100r006:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
h3c magic ba1500l
All versions

CPE

  • cpe:2.3:h:h3c:magic_ba1500l:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-60262
NVD Published Date:
Jan 6, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-60262 Details - Not Deferred