PT-2026-67771 · H3C · Magic R1510+7

CVE-2025-29296

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions H3C Magic BE18000 version V200R007 H3C NX400 version V100R015 H3C Magic NX30 Pro version V100R0011 H3C Magic R3010 version V100R009 H3C Magic NX15 version V100R017 H3C Magic R1510 version V100R016 H3C NE36 Pro version V100R002 H3C MC102G HM1A version V200R010
Description Multiple command injection issues exist in the '/api/esps' request handler. The flaw occurs when attacker-controlled request parameters are incorporated into shell expressions executed by the eval function without adequate validation. This allows a remote attacker to execute arbitrary commands as root and gain complete control of the device. The affected object interfaces and methods include:
  • esps.dhcpd.vlan (getlist, delete)
  • esps.filter.url (add, modify)
  • esps.apcm.version (delete, specifically on H3C Magic NX15)
  • esps.swcm.version (delete, upgrade, on all affected models except H3C Magic NX15)
  • esps.system.ntp (set, on all affected models except H3C Magic NX15)
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-29296

Affected Products

Mc102G Hm1A
Magic Be18000
Magic Nx15
Magic Nx30 Pro
Magic R1510
Magic R3010
Ne36 Pro
Nx400