Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.3% | — | H3C Magic Be18000AIH3C Nx400AIH3C Magic Nx30 PROAIH3C Magic R3010AI+4 | 4/8/2026 | 1/10/2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object… | |
| Analizada | Alta (8.6) | 1.6% | — | H3C Magic Nx15 FirmwareH3C Magic Nx30 PRO FirmwareH3C Magic Nx400 FirmwareH3C Magic R3010 Firmware+1 | 14/4/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler.… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 14/4/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/setLanguage of the component HTTP POST Request Handler. The manipulation leads… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 14/4/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getCapabilityWeb of the component HTTP POST Request Handler. The manipulation… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI | 14/4/2025 | 17/6/2026 | A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classified as critical. This vulnerability affects the function FCGI_WizardProtoProcess of the file /api/wizard/setsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx400AIH3C Magic R3010AI | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_WizardProtoProcess of the file /api/wizard/getsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI | 13/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this issue is the function FCGI_WizardProtoProcess of the file /api/wizard/getSpecs of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI | 13/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this vulnerability is the function FCGI_WizardProtoProcess of the file /api/wizard/getCapability of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 13/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getBasicInfo of the component HTTP POST Request Handler. The manipulation leads to… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. The… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 8.3% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection.… |