CVE-2025-3546 | H3C Magic BE18000 up to V100R014 HTTP POST Request /api/wizard/getLanguage FCGI_CheckStringIfContainsSemicolon command injection
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Impacted is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler. The manipulation results in command injection.
This vulnerability is cataloged as CVE-2025-3546. The attack must originate from the local network. Furthermore, there is an exploit available.
Upgrading the affected component is advised.