CVE-2025-57577

An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a case of misconfiguration if an administrator deliberately ignored the prompts, which is outside the scope of CVE definitions."
Configurations

No configuration.

History

15 Sep 2025, 13:15

Type Values Removed Values Added
References
  • {'url': 'http://h3c.com', 'source': 'cve@mitre.org'}
  • () https://h3c.comĀ -
Summary (en) An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password (en) An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: the Supplier's position is that their "product lines enforce or clearly prompt users to change any initial credentials upon first use. At most, this would be a case of misconfiguration if an administrator deliberately ignored the prompts, which is outside the scope of CVE definitions."

12 Sep 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-12 16:15

Updated : 2025-09-15 15:21


NVD link : CVE-2025-57577

Mitre link : CVE-2025-57577

CVE.ORG link : CVE-2025-57577


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials