References https://zhiliao.h3c.com/theme/details/229784 https://github.com/adysec/POC/blob/main/wpoc/H3C/H3C%E8%B7%AF%E7%94%B1%E5%99%A8userLogin.asp%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md https://www.cnvd.org.cn/flaw/show/CNVD-2025-18039 https://blog.csdn.net/u010025272/article/details/132714547 https://www.gm7.org/archives/50002 https://www.iotsec-zone.com/article/497 https://avd.aliyun.com/detail?id=AVD-2025-61330 https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product/ https://www.h3c.com/en/Products_and_Solutions/IntelligentTerminalProducts/Home_Router/
Related VulnerabilitiesPoCCVE-2025-15403: RegistrationMagic <= 6.0.7.1 - Privilege EscalationPoCCVE-2026-42281: MagicMirror <= 2.35.0 - Server-Side Request ForgeryMagicMirror² /cors 服务器端请求伪造漏洞(CVE-2026-42281)PoCCVE-2021-4073: RegistrationMagic <= 5.0.1.7 - Authentication BypassPoCH3C Magic NX系列设备存在远程命令执行漏洞(CVE-2025-2725)MagicINFO SWUpdateFileUploader 文件上传漏洞三星MagicINFO CVE-2025-4632 文件上传PoCCVE-2010-1307: Joomla! Component Magic Updater - Local File InclusionPoCCVE-2021-24862: WordPress RegistrationMagic <5.0.1.6 - Authenticated SQL InjectionPoCCVE-2021-25864: Hue Magic 3.0.0 - Local File InclusionPoCCVE-2023-33629: H3C Magic R300-2100M - Remote Code ExecutionPoCCVE-2024-7399: Samsung MagicINFO 9 Server 21.1050.0 - Remote Code Execution