Junglewise Threat Intelligence

CVE-2026-15907: H3C SecPath F1000-C8300 SQL injection in log_fw_nbc_mail_jsondata

CVE-2026-15907 · Severity: high · CVSS 7.3 · Published 2026-07-16

Vendors: H3C.

Executive brief

H3C SecPath firewalls are used to protect enterprise networks by monitoring and filtering incoming and outgoing traffic. A security flaw has been identified that could allow an unauthorized person to remotely access or manipulate the device's internal database. This could lead to the exposure of sensitive logs or configuration data, potentially compromising the security of the entire network.

Technical details

A SQL injection vulnerability (CWE-89) exists in the H3C SecPath F1000-C8300 firewall up to version 20260522. The flaw is located within the web management interface, specifically in the '/webui/?g=log_fw_nbc_mail_jsondata' component. An attacker can exploit this by manipulating the 'subject' parameter in a remote request. Successful exploitation allows for unauthorized database queries, which can lead to data exfiltration or modification. The vendor has confirmed the vulnerability and a fix is reportedly planned.

Affected products

  • H3C SecPath F1000-C8300 up to 20260522

Timeline

  • 2026-07-16: advisory: NVD publication date
  • 2026-07-16: disclosed: Public disclosure of the vulnerability and exploit

References