Executive brief
A security vulnerability exists in H3C Magic B0 routers, which are devices used to provide internet connectivity and manage local networks. An attacker can exploit this flaw to cause the device to crash or potentially take full control of the router. This could lead to a total loss of internet service for the connected environment or allow unauthorized access to network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the H3C Magic B0 router firmware up to version 100R002. The flaw is located within the 'SetMobileAPInfoById' function in the '/goform/aspForm' component. The vulnerability is triggered by insufficient length validation when processing the 'param' argument in a POST request. A remote attacker with low privileges can exploit this by sending a specially crafted HTTP request to cause a buffer overflow, potentially leading to a denial of service (DoS) or remote code execution (RCE). Public exploit code (PoC) has been disclosed, and the vendor has reportedly not responded to the disclosure.
Affected products
- H3C Magic B0 Up to 100R002
Timeline
- 2026-06-01: disclosed: Public disclosure of the vulnerability and PoC.
- 2026-06-01: advisory: NVD published the CVE record.