CVE-2025-4998

MEDIUM

H3C Magic R200G < 100R002 - Denial of Service via HTTP POST Request Handler

Title source: llm
STIX 2.1

Description

A vulnerability has been found in H3C Magic R200G up to 100R002 and classified as problematic. Affected by this vulnerability is the function Edit_BasicSSID/Edit_BasicSSID_5G/SetAPWifiorLedInfoById/SetMobileAPInfoById/Asp_SetTimingtimeWifiAndLed/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.309649
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.309649
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.563583

Scores

CVSS v3 6.5
EPSS 0.0044
EPSS Percentile 34.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
H3C/Magic R200G 100R002
Published May 20, 2025
Tracked Since Feb 18, 2026