Junglewise Threat Intelligence

CVE-2025-29296: H3C Magic and NX series command injection in API

CVE-2025-29296 · Severity: critical · CVSS 9.8 · Published 2026-08-04

Vendors: H3C.

Executive brief

Multiple H3C network devices (routers and network appliances) contain command injection vulnerabilities in their web API request handlers. An attacker can send malicious requests to execute arbitrary commands with root privileges, gaining complete control over the affected devices. This could allow an attacker to compromise network infrastructure, access sensitive data, or disrupt network operations.

Technical details

Multiple command injection vulnerabilities exist in the /api/esps request handler across several H3C device models. Attacker-controlled parameters in esps.dhcpd.vlan, esps.filter.url, esps.apcm.version, esps.swcm.version, and esps.system.ntp interfaces are incorporated into shell expressions executed via eval without adequate validation. The vulnerabilities are reachable remotely via the web API and do not require authentication. Successful exploitation allows arbitrary command execution as root, leading to complete device compromise. Patches are expected from H3C.

Affected products

  • H3C Magic BE18000 V200R007
  • H3C NX400 V100R015
  • H3C Magic NX30 Pro V100R0011
  • H3C Magic R3010 V100R009
  • H3C Magic NX15 V100R017
  • H3C Magic R1510 V100R016
  • H3C NE36 Pro V100R002
  • H3C MC102G HM1A0 V200R010

Timeline

  • 2026-08-04: disclosed

References