PT-2026-24667 · H3C · Acg1000-Ak230
Leeyper
+1
·
Publicado
2026-03-11
·
Atualizado
2026-03-15
·
CVE-2026-3943
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
H3C ACG1000-AK230 versions up to 20260227
Description
A flaw exists in H3C ACG1000-AK230 that allows for command injection. The issue is located in an unknown part of the file
/webui/?aaa portal auth local submit. Manipulation of the suffix argument in this file can lead to remote code execution. The exploit for this issue has been publicly released.Recommendations
Versions up to 20260227 should be updated when a fix becomes available. As a temporary workaround, consider restricting access to the
/webui/?aaa portal auth local submit file to minimize the risk of exploitation.Exploit
Correção
Command Injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Acg1000-Ak230