PT-2026-24667 · H3C · Acg1000-Ak230
Leeyper
+1
·
Published
2026-03-11
·
Updated
2026-03-15
·
CVE-2026-3943
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
H3C ACG1000-AK230 versions up to 20260227
Description
A flaw exists in H3C ACG1000-AK230 that allows for command injection. The issue is located in an unknown part of the file
/webui/?aaa portal auth local submit. Manipulation of the suffix argument in this file can lead to remote code execution. The exploit for this issue has been publicly released.Recommendations
Versions up to 20260227 should be updated when a fix becomes available. As a temporary workaround, consider restricting access to the
/webui/?aaa portal auth local submit file to minimize the risk of exploitation.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acg1000-Ak230