Junglewise Threat Intelligence

CVE-2025-63258: H3C Multiple Routers and Gateways Command Injection in sessionid

CVE-2025-63258 · Severity: medium · CVSS 6.5 · Published 2025-11-18

Vendors: H3C.

Executive brief

A security vulnerability has been identified in several H3C networking devices, including business-grade routers, wireless access points, and cloud gateways. This flaw allows an attacker to bypass security protections and remotely execute commands on the device by sending a specially crafted web request. If exploited, an attacker could gain unauthorized access to sensitive device information or disrupt network operations.

Technical details

A remote command execution (RCE) vulnerability exists in multiple H3C networking products due to improper neutralization of special elements in the 'sessionid' parameter (CWE-77). An unauthenticated attacker can exploit this by sending a crafted POST request to the device's management interface. This allows the attacker to bypass authentication and execute arbitrary commands on the underlying operating system. The vulnerability affects ERG3, ERG5, UR, and XiaoBei series routers, as well as specific MSG, USG, UAP, and WAP models. H3C has released firmware version Release 0162P11 to address this issue for the ERG3 and UR series; users are advised to upgrade or disable remote Web and Telnet management as a temporary mitigation.

Affected products

  • H3C ERG3 Series Routers Release 0162P07 and earlier
  • H3C ERG5 Series Routers All versions
  • H3C UR Series Routers Release 0162P10 and earlier
  • H3C XiaoBei Series Routers All versions
  • H3C Cloud Gateways (MSG300/MSG326/USG300V2) MSG300-WPT330-R1350, MSG326-WPT330-R2129, USG300V2-WPT330-R2129
  • H3C Wireless Access Points (UAP/WAP series) UAP700-WPT330-E2265, UAP672-WPT330-R2262, UAP662E-WPT330-R2262P03, WAP611-WPT330-R1348-OASIS, WAP662-WPT330-R2262, WAP662H-WPT330-R2262

Timeline

  • 2025-11-14: advisory: H3C published the security advisory and fix details
  • 2025-11-18: disclosed: CVE-2025-63258 published to NVD

References