What is CVE-2025-29296?
These vulnerabilities are command injection flaws found in the /api/esps request handler of multiple H3C router models. Affected devices can be targeted via specially crafted network requests. Access to remote management interfaces should be restricted until patches are provided by the vendor.
Azərbaycanca: Bu zəifliklər H3C-nin bir neçə marşrutlaşdırıcı modelində /api/esps request handler-da aşkarlanmış command injection boşluqlarıdır. Cihazlar şəbəkə üzərindən xüsusi hazırlanmış sorğularla hədəf alına bilər. İstehsalçı tərəfindən yamaq təmin olunana qədər bu cihazların uzaqdan idarə interfeyslərinə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: H3C
FAQ2
How can devices affected by CVE-2025-29296 be targeted?
The affected H3C routers can be targeted by sending specially crafted network requests to the /api/esps request handler.
What mitigation should be applied for CVE-2025-29296 until a patch is provided by the vendor?
Access to the remote management interfaces of these devices should be restricted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.