We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this issue. Because they assess the risk as low, they do not have immediate plans for remediation.
Es wurde eine kritische Schwachstelle in H3C GR-3000AX V100R007L50 ausgemacht. Dabei betrifft es die Funktion UpdateWanParamsMulti/UpdateIpv6Params der Datei /routing/goform/aspForm. Durch Manipulation des Arguments param mit unbekannten Daten kann eine buffer overflow-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
2025-06-14: | VulDB entry created |
2025-06-15: | Advisory disclosed |
2025-06-15: | VulDB entry last update |
CH13hh (VulDB User)
vuldb.com/?id.312558 (VDB-312558 | H3C GR-3000AX aspForm UpdateIpv6Params buffer overflow)
vuldb.com/?ctiid.312558 (VDB-312558 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.588000 (Submit #588000 | H3C H3C GR-3000AX V100R007L50 Buffer Overflow)
github.com/CH13hh/cve/blob/main/new/6.md
Support options