CVE-2026-10259: H3C Magic B0 aspForm SetMobileAPInfoById stack-based overflow
A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or limit network access to the device web management interface, specifically blocking requests to /goform/aspForm at the network perimeter or firewall. Allow management access only from trusted IPs or management networks.
- Compensating control
Prevent direct Internet access to the device: block inbound HTTP/HTTPS and other management ports to the H3C Magic B0 from untrusted networks, or require VPN/management jump host for administrative access.
- Compensating control
Deploy network detection and prevention controls (IDS/IPS/WAF) to detect and block exploitation attempts targeting the SetMobileAPInfoById function or requests to /goform/aspForm and related malicious payloads.
- Operational
Monitor device logs and network traffic for requests to /goform/aspForm and signs of exploitation (crashes, unexpected reboots, anomalous payloads). If compromise is suspected, isolate the device from the network and perform recovery actions such as taking the device offline and reimaging or factory-resetting before returning it to service.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10259?
The severity of CVE-2026-10259 is rated as high with a score of 7.4.
How do I fix CVE-2026-10259?
To fix CVE-2026-10259, update your H3C Magic B0 device to the latest firmware version beyond 100R002.
What type of vulnerability is CVE-2026-10259?
CVE-2026-10259 is a stack-based buffer overflow vulnerability.
Can CVE-2026-10259 be exploited remotely?
Yes, CVE-2026-10259 can be exploited remotely.
What function is affected by CVE-2026-10259?
The function affected by CVE-2026-10259 is SetMobileAPInfoById located in the file /goform/aspForm.