Impact
A buffer overflow flaw exists in the SetAPWifiorLedInfoById function of the H3C Magic B1 web interface, allowing an attacker to send crafted input that may overflow a buffer and execute arbitrary code. The vulnerability is rated with a CVSS score of 8.7, indicating high severity and a significant potential impact on confidentiality, integrity, and availability.
Affected Systems
H3C Magic B1 routers running firmware versions up to 100R004 are affected. The flaw resides in the /goform/aspForm endpoint of the device’s web management interface.
Risk and Exploitability
The flaw can be triggered remotely by sending malicious requests to the vulnerable endpoint. EPSS data is not available and the issue is not listed in CISA’s KEV catalog, but the public disclosure and the vulnerability’s high CVSS score suggest that it is likely to be exploited by adversaries with sufficient interest. Because the vendor has not issued a public fix, the attack surface remains open until a patch is applied or mitigations are enforced.
OpenCVE Enrichment