PT-2026-23912 · H3C · H3C Magic B1St
Sftian
+1
·
Published
2026-03-08
·
Updated
2026-03-13
·
CVE-2026-3701
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
H3C Magic B1 versions up to 100R004
Description
A security issue exists in H3C Magic B1. A buffer overflow can occur in the
Edit BasicSSID 5G function within the /goform/aspForm file due to manipulation of the param argument. This allows for remote execution of code. The exploit for this issue has been publicly disclosed. The vendor was notified but did not respond.Recommendations
Versions up to 100R004 should be updated to a newer, secure version when available. As a temporary workaround, consider restricting access to the
/goform/aspForm file to minimize the risk of exploitation. Avoid using the param argument in the Edit BasicSSID 5G function until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H3C Magic B1St