Home

Description

EN DE

A vulnerability has been found in H3C GR-5400AX up to 100R008 and classified as critical. This vulnerability affects the function Edit_List_SSID of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack needs to be approached within the local network.

In H3C GR-5400AX bis 100R008 wurde eine kritische Schwachstelle gefunden. Das betrifft die Funktion Edit_List_SSID der Datei /goform/aspForm. Dank Manipulation des Arguments param mit unbekannten Daten kann eine buffer overflow-Schwachstelle ausgenutzt werden. Der Angriff kann im lokalen Netzwerk angegangen werden.

PUBLISHED Reserved 2025-05-08 | Published 2025-05-09 | Updated 2025-05-09 | Assigner VulDB




HIGH: 8.6CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.0CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
HIGH: 8.0CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.7AV:A/AC:L/Au:S/C:C/I:C/A:C

Problem types

Buffer Overflow

Memory Corruption

Product status

100R008
affected

Timeline

2025-05-08:Advisory disclosed
2025-05-08:VulDB entry created
2025-05-08:VulDB entry last update

Credits

BabyShark (VulDB User) reporter

References

vuldb.com/?id.308056 (VDB-308056 | H3C GR-5400AX aspForm Edit_List_SSID buffer overflow) vdb-entry technical-description

vuldb.com/?ctiid.308056 (VDB-308056 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.561866 (Submit #561866 | New H3C Technologies Co., Ltd. GR-5400AX <=100R008 Buffer Overflow) third-party-advisory

github.com/CH13hh/tmp_store_cc/blob/main/H3C GB5400AX/5.md related

cve.org (CVE-2025-4446)

nvd.nist.gov (CVE-2025-4446)

Download JSON