CVE-2025-4997

MEDIUM

H3C R2+ProG < 200R004 - Denial of Service via UpdateWanParams Function

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.309648
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.309648
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.563551

Scores

CVSS v3 6.5
EPSS 0.0044
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
H3C/R2+ProG 200R004
Published May 20, 2025
Tracked Since Feb 18, 2026