CVE-2025-29296
Received Received - Intake

Command Injection in H3C Network Devices

Vulnerability report for CVE-2025-29296, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: MITRE

Description

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H3C NE36 Pro V100R002 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object interfaces and methods are esps.dhcpd.vlan (getlist, delete), esps.filter.url (add, modify), esps.apcm.version (delete, H3C Magic NX15 only), esps.swcm.version (delete, upgrade, all affected models except H3C Magic NX15), and esps.system.ntp (set, all affected models except H3C Magic NX15). Attacker-controlled request parameters are incorporated into shell expressions executed by eval without adequate validation, allowing a remote attacker to execute arbitrary commands as root and gain complete control of the affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
h3c magic_be18000 v200r007
h3c nx400 v100r015
h3c magic_nx30_pro v100r0011
h3c magic_r3010 v100r009
h3c magic_nx15 v100r017
h3c magic_r1510 v100r016
h3c ne36_pro v100r002

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves multiple command injection flaws in H3C devices. Attackers can exploit these by sending crafted requests to the /api/esps endpoint. The system executes shell commands without proper input validation, allowing remote attackers to run arbitrary commands as root and take full control of the device.

Detection Guidance

Detecting this vulnerability requires checking for vulnerable H3C devices and inspecting network traffic for suspicious /api/esps requests. Use network scanning tools like Nmap to identify affected H3C devices by their CPEs. Monitor HTTP POST/GET requests to /api/esps endpoints for parameters like esps.dhcpd.vlan, esps.filter.url, or esps.system.ntp. Look for unusual command patterns or eval-related payloads in request bodies.

Impact Analysis

If you use any of the affected H3C devices, an attacker could gain complete control over your device. This could lead to unauthorized access, data theft, network compromise, or disruption of services. The impact includes potential loss of confidentiality, integrity, and availability of the device and connected systems.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other regulations due to unauthorized access and data breaches. Organizations may face legal penalties, loss of trust, and reputational damage if exploited. Affected devices should be patched immediately to maintain compliance.

Mitigation Strategies

Immediately apply vendor patches or updates for the affected H3C devices. Disable or restrict access to the vulnerable API endpoints (/api/esps) if patches are unavailable. Implement network segmentation to isolate vulnerable devices. Monitor network traffic for suspicious activity targeting these endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-29296. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart