Record summary

CVE-2023-33629 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHH3C Magic R300-2100M - Remote Code ExecutionCVSS 7.2

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.

Impact

Authenticated high-privilege attackers can exploit stack overflow through command injection in the DelL2tpLNSList parameter to execute arbitrary commands on the H3C Magic R300 router with root privileges.

Remediation

Update H3C Magic R300-2100M firmware to a version newer than R300-2100MV100R004 that properly validates input in the DeltriggerList interface at /goform/aspForm.

WeaknessesCWE-787
AuthorsDhiyaneshDK
Template tagscve2023cverouterrceh3cvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:h3c:magic_r300-2100m_firmware:r300-2100mv100r004:*:*:*:*:*:*:*
FOFA: app="H3C-Ent-Router"
FOFA: app="h3c-ent-router"

Source: ProjectDiscovery

References

3