PT-2026-24667 · H3C · Acg1000-Ak230

Leeyper

+1

·

Publicado

2026-03-11

·

Atualizado

2026-03-15

·

CVE-2026-3943

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions H3C ACG1000-AK230 versions up to 20260227
Description A flaw exists in H3C ACG1000-AK230 that allows for command injection. The issue is located in an unknown part of the file /webui/?aaa portal auth local submit. Manipulation of the suffix argument in this file can lead to remote code execution. The exploit for this issue has been publicly released.
Recommendations Versions up to 20260227 should be updated when a fix becomes available. As a temporary workaround, consider restricting access to the /webui/?aaa portal auth local submit file to minimize the risk of exploitation.

Exploit

Correção

Command Injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3943

Produtos afetados

Acg1000-Ak230