Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Magic NX15 — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Magic NX15, with AI-generated Chinese analysis, references, and POCs.

This page documents known software vulnerabilities for Magic NX15, categorized under various weakness types and tagged for precise identification. It collects a comprehensive list of security flaws affecting the Magic NX15 product, covering reports published from the early days of the software’s lifecycle up to the most recent disclosures. By aggregating these entries, the resource allows users to track vendor advisories, understand specific weakness classes such as buffer overflows or injection flaws, and look up a product's vulnerability history to assess its overall security posture over time. The data includes details on affected versions, severity ratings, and potential mitigation strategies where available. This centralized view helps security professionals, system administrators, and developers evaluate risks associated with Magic NX15 deployments without needing to cross-reference multiple disparate sources. The information is organized to facilitate quick lookup and analysis, ensuring that stakeholders can make informed decisions regarding patching, upgrades, or configuration changes. Regular updates are performed to reflect new findings and corrected data, maintaining the accuracy and relevance of the content. Users are encouraged to consult this page as a reference point for understanding the security landscape surrounding Magic NX15 and to support their internal risk management processes. All entries are sourced from verified advisories and public vulnerability databases to ensure reliability and consistency in the presented information.

Vendor: H3C

CVE IDTitleCVSSSeverityPublished
CVE-2025-3546 H3C Magic BE18000 HTTP POST Request getLanguage FCGI_CheckStringIfContainsSemicolon command injection CWE-77 8.0 High2025-04-14
CVE-2025-3545 H3C Magic BE18000 HTTP POST Request setLanguage FCGI_CheckStringIfContainsSemicolon command injection CWE-77 8.0 High2025-04-14
CVE-2025-3544 H3C Magic BE18000 HTTP POST Request getCapabilityWeb FCGI_CheckStringIfContainsSemicolon command injection CWE-77 8.0 High2025-04-14
CVE-2025-3543 H3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request setsyncpppoecfg FCGI_WizardProtoProcess command injection CWE-77 8.0 High2025-04-14
CVE-2025-3542 H3C Magic NX15/Magic NX400/Magic R3010 HTTP POST Request getsyncpppoecfg FCGI_WizardProtoProcess command injection CWE-77 8.0 High2025-04-13
CVE-2025-3541 H3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getSpecs FCGI_WizardProtoProcess command injection CWE-77 8.0 High2025-04-13
CVE-2025-3540 H3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getCapability FCGI_WizardProtoProcess command injection CWE-77 8.0 High2025-04-13
CVE-2025-3539 H3C Magic BE18000 HTTP POST Request getBasicInfo FCGI_CheckStringIfContainsSemicolon command injection CWE-77 8.0 High2025-04-13
CVE-2025-2732 H3C Magic BE18000 HTTP POST Request getWifiNeighbour command injection CWE-77 8.0 High2025-03-25
CVE-2025-2731 H3C Magic BE18000 HTTP POST Request getDualbandSync command injection CWE-77 8.0 High2025-03-25
CVE-2025-2730 H3C Magic BE18000 HTTP POST Request getssidname command injection CWE-77 8.0 High2025-03-25
CVE-2025-2729 H3C Magic BE18000 HTTP POST Request networkSetup command injection CWE-77 8.0 High2025-03-25
CVE-2025-2726 H3C Magic BE18000 HTTP POST Request esps command injection CWE-77 8.0 High2025-03-25
CVE-2025-2725 H3C Magic BE18000 HTTP POST Request auth command injection CWE-77 8.0 High2025-03-25

All 14 known CVE vulnerabilities affecting Magic NX15 with full Chinese analysis, references, and POCs where available.