CVE-2024-32238

CRITICAL EXPLOITED NUCLEI

H3C ER8300G2-X - Info Disclosure

Title source: llm

Description

H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.

Exploits (2)

nomisec WORKING POC 1 stars
by FuBoLuSec · infoleak
https://github.com/FuBoLuSec/CVE-2024-32238

Nuclei Templates (1)

H3C ER8300G2-X - Password Disclosure
CRITICALVERIFIEDby s4e-io,adeljck
FOFA: body="icg_helpScript.js"

Scores

CVSS v3 9.8
EPSS 0.8967
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2025-02-27

Classification

CWE
CWE-522
Status draft

Timeline

Published Apr 22, 2024
Tracked Since Feb 18, 2026