CVE-2025-8907 describes a local privilege escalation vulnerability in the Webserver Configuration component of H3C M2 NAS V100R006, affecting an unknown functionality. The vulnerability has a CVSS score of 7.0 (High), indicating significant impact with high confidentiality, integrity, and availability compromise, despite a high attack complexity. Exploitation requires local access and is considered difficult, with public disclosure of the exploit. However, the vendor states the device lacks "boa functionality" and the vulnerability only impacts unsupported products, leading to minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| H3C | M2 NAS | V100R006CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.