PT-2025-20437 · H3C · H3C Gr-1800Ax

Babyshark

·

Published

2025-05-08

·

Updated

2025-05-09

·

CVE-2025-4440

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions H3C GR-1800AX versions up to 100R008
Description A critical issue was found, affecting the function EnableIpv6 of the file "/goform/aspForm". The manipulation of the argument param leads to a buffer overflow. Access to the local network is required for this attack to succeed. The exploit has been disclosed to the public and may be used.
Recommendations For H3C GR-1800AX versions up to 100R008, consider disabling the EnableIpv6 function of the "/goform/aspForm" file as a temporary workaround until a patch is available. Restrict access to the local network to minimize the risk of exploitation. Avoid using the param argument in the affected file until the issue is resolved.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-4440

Affected Products

H3C Gr-1800Ax