In H3C MagicR100 <=V100R005, the / Ajax / ajaxget interface can be accessed without authorization. It sends a large amount of data through ajaxmsg to carry out DOS attack.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Magic_r100_firmware |
H3c |
* |
v100r005 (including) |
References