A vulnerability labeled as very critical has been found in H3C Magic BE18000, Magic NX400, Magic NX30 Pro, Magic R3010, Magic NX15, Magic R1510 and NE36 Pro up to V200R007. Affected by this issue is some unknown functionality of the file /api/esps of the component esps.dhcpd.vlan/esps.filter.url/esps.apcm.version/esps.swcm.version/esps.system.ntp. Such manipulation leads to command injection.

This vulnerability is uniquely identified as CVE-2025-29296. The attack can be launched remotely. No exploit exists.