PT-2026-33619 · H3C · Magic B1

Kunlun

·

Published

2026-04-19

·

Updated

2026-04-19

·

CVE-2026-6581

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-6581

Affected Products

Magic B1