CVE-2025-44653
Published Jul 21, 2025In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected.
- evidence mentions
- 2
- Buzz score
- 17.5
Vendor/product archive
2 CVEs tagged to h3c / gr2200_firmware — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected.
H3C GR2200 MiniGR1A0V100R014 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.