A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical. Affected by this issue is the function EditWlanMacList of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Wed, 04 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared H3c
H3c gr-5400ax
H3c gr-5400ax Firmware
CPEs cpe:2.3:h:h3c:gr-5400ax:-:*:*:*:*:*:*:*
cpe:2.3:o:h3c:gr-5400ax_firmware:*:*:*:*:*:*:*:*
Vendors & Products H3c
H3c gr-5400ax
H3c gr-5400ax Firmware

Wed, 28 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 25 May 2025 22:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical. Affected by this issue is the function EditWlanMacList of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title H3C GR-5400AX aspForm EditWlanMacList buffer overflow
Weaknesses CWE-119
CWE-120
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-25T22:00:08.568Z

Updated: 2025-05-28T17:38:00.978Z

Reserved: 2025-05-25T06:48:29.689Z

Link: CVE-2025-5156

cve-icon Vulnrichment

Updated: 2025-05-27T14:20:59.375Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-25T22:15:19.673

Modified: 2025-06-03T15:49:18.683

Link: CVE-2025-5156

cve-icon Redhat

No data.