Impact
A location‑based SQL injection exists in the /webui/?g=log_fw_nbc_mail_jsondata endpoint of H3C SecPath F1000‑C8300. By manipulating the subject argument, an attacker can embed malicious SQL expressions. The flaw results from improper input validation (CWE‑74) and unsafe query construction (CWE‑89). Successful exploitation could allow the attacker to read, modify or delete database records, leading to confidentiality, integrity or availability compromise.
Affected Systems
The vulnerability affects all H3C SecPath F1000‑C8300 appliances running firmware versions up to and including 20260522. The exposed endpoint is part of the web UI, and the unknown function impacted by the error indicates that any device with that firmware level is potentially affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The risk is not listed in CISA KEV. The exploit is remote and has already been published, so attackers could target any network exposing the web UI to the internet. The attack vector requires network access to the device’s web service and does not need local privileges.
OpenCVE Enrichment