← voltar
CVE-2025-6091

H3C GR-3000AX aspForm UpdateIpv6Params buffer overflow

CVSS 8.7 HIGHEPSS 0.5%CWE-119CWE-120
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.7EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
15 jun 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function UpdateWanParamsMulti/UpdateIpv6Params of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this issue. Because they assess the risk as low, they do not have immediate plans for remediation.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Produtos afetados
H3C · GR-3000AX

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →