H3C ERG3
cpe:2.3:h:h3c:b5_mini:*:*:*:*:*:*:*, +31 more
- <= R0162P07
A remote command execution vulnerability has been identified in H3C ERG3/ERG5 series routers, XiaoBei series routers, cloud gateways, and wireless access points. This vulnerability affects specific versions of these products, including H3C ERG3 series and UR series devices. The issue arises when devices are configured to allow remote management, enabling attackers to inject crafted commands that bypass security authentication and access sensitive information from the device.
Exploitation of this vulnerability allows for remote command execution on the affected devices, potentially leading to unauthorized access and manipulation of device functions or data.
Users are advised to upgrade to H3C ERG3 series Release 0162P11 or H3C UR series Release 0162P11. For temporary mitigation, remote Web management and Telnet management features can be disabled, although the former is off by default.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.