Executive brief
A security vulnerability exists in the H3C Magic B0 router, a device used for wireless networking. An attacker can exploit this flaw to crash the router's management interface or potentially take full control of the device. This could lead to a complete loss of internet connectivity for the network or unauthorized access to network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the H3C Magic B0 router (firmware <= 100R002). The flaw is located within the Edit_BasicSSID_5G function in the /goform/aspForm handler. The root cause is a lack of boundary checks when processing the 'param' argument, where user-supplied input is copied into a fixed-size buffer using unsafe memory operations. An authenticated attacker can trigger this vulnerability by sending a specially crafted POST request. Successful exploitation can lead to a crash of the web management service, device instability, or potential remote code execution. A public exploit (PoC) is available, and the vendor has not yet released a patch.
Affected products
- H3C Magic B0 Router up to 100R002
Timeline
- 2026-04-26: disclosed: Vulnerability details and PoC published on GitHub.
- 2026-05-24: advisory: CVE-2026-9393 published.