CVE-2023-33629
h3c magic_r300-2100m_firmware Out-of-bounds Write
Record summary
CVE-2023-33629 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 7, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 10, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
magic_r300-2100m_firmwareBrowse h3c / magic_r300-2100m_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHH3C Magic R300-2100M - Remote Code ExecutionCVSS 7.2
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.
Impact
Authenticated high-privilege attackers can exploit stack overflow through command injection in the DelL2tpLNSList parameter to execute arbitrary commands on the H3C Magic R300 router with root privileges.
Remediation
Update H3C Magic R300-2100M firmware to a version newer than R300-2100MV100R004 that properly validates input in the DeltriggerList interface at /goform/aspForm.
Source: ProjectDiscovery