PT-2026-23912 · H3C · H3C Magic B1St
Sftian
+1
·
Publicado
2026-03-08
·
Atualizado
2026-03-13
·
CVE-2026-3701
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
H3C Magic B1 versions up to 100R004
Description
A security issue exists in H3C Magic B1. A buffer overflow can occur in the
Edit BasicSSID 5G function within the /goform/aspForm file due to manipulation of the param argument. This allows for remote execution of code. The exploit for this issue has been publicly disclosed. The vendor was notified but did not respond.Recommendations
Versions up to 100R004 should be updated to a newer, secure version when available. As a temporary workaround, consider restricting access to the
/goform/aspForm file to minimize the risk of exploitation. Avoid using the param argument in the Edit BasicSSID 5G function until the issue is resolved.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
H3C Magic B1St