PT-2025-17476 · H3C · H3C Gr-3000Ax
CVSS v2.0
7.7
High
| Vector | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
H3C GR-3000AX versions prior to V100R006
Description
A critical issue exists in the HTTP POST Request Handler component within the
/goform/aspForm file. The vulnerability is caused by a buffer overflow—a condition where a program writes more data to a block of memory than it can hold—due to insufficient validation of input size. This occurs when manipulating the param variable within the functions EnableIpv6(), UpdateWanModeMulti(), UpdateIpv6Params(), EditWlanMacList(), and Edit List SSID(). An attacker located within the local network can exploit this to execute arbitrary code. Other functions may also be affected.Recommendations
Upgrade the affected component to a version newer than V100R006.
As a temporary mitigation, restrict access to the
/goform/aspForm endpoint to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H3C Gr-3000Ax