logo

CVE-2025-60262: Critical Misconfiguration in H3C Wireless Gear Hands Control to Hackers

ID: b853a672-a1ec-5604-b946-a271d7ad89c0

STIX ID: report--b853a672-a1ec-5604-b946-a271d7ad89c0

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Ddos

...
...

A critical misconfiguration in H3C devices (M102G Wireless Controller and BA1500L Access Point) enables anonymous FTP uploads to be automatically owned by root (CVE-2025-60262, CVSS 9.8), allowing remote attackers with anonymous FTP access to achieve root-level control; administrators should verify firmware versions and apply vendor fixes when available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.