A vulnerability, which was classified as problematic, was found in H3C R2+ProG up to 200R004. Affected is the function
UpdateWanParams/AddMacList/EditMacList/AddWlanMacList/EditWlanMacList/Edit_BasicSSID/Edit_GuestSSIDFor2P4G/Edit_BasicSSID_5G/SetAPInfoById
of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argument param leads to denial of service.
This vulnerability is traded as CVE-2025-4997. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.