CVE-2025-2728: h3c Magic NX30 Pro
High severity, CVSS 8.0. EPSS: 1% chance of exploitation in the next 30 days.
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs to be approached within the local network. It is recommended to upgrade the affected component.
Affected products
Published 2025-03-25. Last modified 2026-06-17.