CVE-2025-60262
Misconfigured vsftpd in H3C Devices Allows Root Access
Publication date: 2026-01-06
Last updated on: 2026-01-06
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| h3c | m102g_hm1a0v200r010 | * |
| h3c | ba1500l_swba1a0v100r006 | * |
| unknown_vendor | vsftpd | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a misconfiguration issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point related to vsftpd. It causes all files uploaded anonymously via the FTP protocol to be automatically owned by the root user, allowing remote attackers to gain root-level control over the affected devices.
How can this vulnerability impact me? :
The vulnerability can allow remote attackers to gain root-level control over the affected devices, which means they can fully control the device, potentially leading to unauthorized access, data theft, device manipulation, or disruption of services.