H3C · H3C Magic B1St · CVE-2026-3701
**Name of the Vulnerable Software and Affected Versions**
H3C Magic B1 versions up to 100R004
**Description**
A security issue exists in H3C Magic B1. A buffer overflow can occur in the `Edit BasicSSID 5G` function within the `/goform/aspForm` file due to manipulation of the `param` argument. This allows for remote execution of code. The exploit for this issue has been publicly disclosed. The vendor was notified but did not respond.
**Recommendations**
Versions up to 100R004 should be updated to a newer, secure version when available. As a temporary workaround, consider restricting access to the `/goform/aspForm` file to minimize the risk of exploitation. Avoid using the `param` argument in the `Edit BasicSSID 5G` function until the issue is resolved.