CVE-2025-60262 Details
Description
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.
A misconfiguration vulnerability has been identified in the H3C M102G HM1A0V200R010 wireless controller and the BA1500L SWBA1A0V100R006 wireless access point. This vulnerability involves vsftpd, where files uploaded anonymously via FTP are automatically assigned to the root user. As a result, remote attackers could potentially gain root-level control over the affected devices.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.notion.so/23e54a1113e780d686fbe1624ee0465d | [email protected] | ExploitThird Party Advisory |
| https://www.notion.so/Misconfiguration-in-H3C-23e54a1113e780d686fbe1624ee0465d | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| h3c mc102-g firmware | hm1a0v200r010 |
CPE
Remediation
| |
| h3c mc102-g | All versions |
CPE
Remediation
| |
| h3c magic ba1500l firmware | swba1a0v100r006 |
CPE
Remediation
| |
| h3c magic ba1500l | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 29, 2026 | Initial Analysis | [email protected] |
| Jan 6, 2026 | New CVE Received | [email protected] |
| Jan 6, 2026 | CVE Modified | CISA-ADP |