CVE-2025-60262

CRITICAL EPSS 38.5%
Published Jan 6, 20265mo ago · Modified Jun 17, 20261w ago
9.8 CVSS 3.1
Critical
Find Similar
Published Jan 6, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago

Description

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.

CVSS Details

Base Score
9.8
Exploitability
3.9
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
38.5% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available

Weaknesses 1

CWE-276

Affected Products 4

VendorProductVersionRange
h3cmc102-g_firmwarehm1a0v200r010any
h3cmc102-g*any
h3cmagic_ba1500l_firmwareswba1a0v100r006any
h3cmagic_ba1500l*any

References 2

  • notion.so https://www.notion.so/23e54a1113e780d686fbe1624ee0465d
    ExploitThird Party Advisory
  • notion.so https://www.notion.so/Misconfiguration-in-H3C-23e54a1113e780d686fbe1624ee0465d
    ExploitThird Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.