CVE-2026-15907: H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=logfwnbcmailjsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. A technical fix is planned to be released.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-15907?
CVE-2026-15907 is a high-severity SQL injection vulnerability in H3C SecPath F1000-C8300 that affects the /webui/?g=log_fw_nbc_mail_jsondata function.
What is the severity of CVE-2026-15907?
The severity of CVE-2026-15907 is classified as high with a score of 7.3.
How do I fix CVE-2026-15907?
To fix CVE-2026-15907, update H3C SecPath F1000-C8300 to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-15907?
CVE-2026-15907 is categorized as a SQL injection vulnerability.
Can CVE-2026-15907 be exploited remotely?
Yes, CVE-2026-15907 can be exploited remotely through manipulation of the argument subject.