CVE-2025-14015

HIGH

H3C Magic B0 Firmware < 100R002 - Memory Corruption

Title source: rule
STIX 2.1

Description

A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.334256
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.334256
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.694755

Scores

CVSS v3 8.8
EPSS 0.0021
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
h3c/magic_b0_firmware < 100R002
Published Dec 04, 2025
Tracked Since Feb 18, 2026