PT-2025-20444 · H3C · H3C Gr-5400Ax
Babyshark
·
Published
2025-05-08
·
Updated
2025-05-14
·
CVE-2025-4446
CVSS v2.0
7.7
High
| Vector | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
H3C GR-5400AX versions up to 100R008
Description
A critical issue has been found that affects the Edit List SSID function of the /goform/aspForm file. The manipulation of the
param argument leads to a buffer overflow. This issue can be exploited within the local network.Recommendations
For H3C GR-5400AX versions up to 100R008, as a temporary workaround, consider restricting access to the /goform/aspForm file until a patch is available.
Avoid using the
param argument in the affected function Edit List SSID until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H3C Gr-5400Ax