CVE-2025-3854 | H3C GR-3000AX up to V100R006 HTTP POST Request /goform/aspForm param buffer overflow
A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6Params/EditWlanMacList/Edit_List_SSID of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to buffer overflow.
This vulnerability is traded as CVE-2025-3854. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
Other functions might be affected as well.