Executive brief
A configuration issue in H3C GR2200 enterprise routers allows for a denial-of-service condition. The device's file transfer service is configured to allow an unlimited number of simultaneous connections, which can be exploited to exhaust system resources. This could result in the router becoming unresponsive, disrupting network connectivity and business operations.
Technical details
The H3C GR2200 router (firmware MiniGR1A0V100R016) contains a resource exhaustion vulnerability (CWE-400) due to an insecure default configuration in the bftpd FTP server. The 'USERLIMIT_GLOBAL' parameter in /etc/bftpd.conf is set to 0, which disables the limit on concurrent global connections. A remote, unauthenticated attacker can exploit this by initiating a large number of simultaneous FTP connections to the device. This leads to a denial-of-service (DoS) state by consuming all available system resources or connection slots, preventing legitimate administrative or network traffic.
Affected products
- H3C GR2200 MiniGR1A0V100R016
Timeline
- 2025-07-21: disclosed
- 2025-07-21: advisory