PT-2026-41584 · H3C · Magic B3
Yyy0032
·
Published
2026-05-17
·
Updated
2026-05-18
·
CVE-2026-8764
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
H3C Magic B3 versions prior to 100R002
Description
A buffer overflow exists in the
UpdateWanParams() function within the '/goform/aspForm' endpoint. This issue occurs when the param argument is manipulated, allowing a remote attacker to trigger the overflow.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/goform/aspForm' endpoint or avoid using the
param argument within the UpdateWanParams() function.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Magic B3