Stack-Based Buffer Overflow Vulnerability in H3C Magic B0 by H3C
CVE-2026-10259
Key Information:
Badges
What is CVE-2026-10259?
A vulnerability has been identified in the H3C Magic B0 device, specifically affecting versions up to 100R002. The issue arises within the SetMobileAPInfoById function of the /goform/aspForm file, where improper handling of the argument param enables attackers to exploit a stack-based buffer overflow. This vulnerability can be triggered remotely, posing significant risks to users and their systems. Despite being notified early, the vendor has not responded. To remediate, it is crucial to implement the necessary security measures and updates as they become available.
Affected Version(s)
Magic B0 100R002
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved