PT-2026-23912 · H3C · H3C Magic B1St

Sftian

+1

·

Published

2026-03-08

·

Updated

2026-03-13

·

CVE-2026-3701

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions H3C Magic B1 versions up to 100R004
Description A security issue exists in H3C Magic B1. A buffer overflow can occur in the Edit BasicSSID 5G function within the /goform/aspForm file due to manipulation of the param argument. This allows for remote execution of code. The exploit for this issue has been publicly disclosed. The vendor was notified but did not respond.
Recommendations Versions up to 100R004 should be updated to a newer, secure version when available. As a temporary workaround, consider restricting access to the /goform/aspForm file to minimize the risk of exploitation. Avoid using the param argument in the Edit BasicSSID 5G function until the issue is resolved.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-3701

Affected Products

H3C Magic B1St