CVE-2025-10942

HIGH

H3C Magic B3 <100R002 - Buffer Overflow

Title source: llm
STIX 2.1

Description

A vulnerability was identified in H3C Magic B3 up to 100R002. This affects the function AddMacList/EditMacList of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.325812
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.325812
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.651813
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.684667

Scores

CVSS v3 8.8
EPSS 0.0043
EPSS Percentile 62.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
H3C/Magic B3 100R002
Published Sep 25, 2025
Tracked Since Feb 18, 2026