CVE-2026-6560: H3C Magic B0 aspForm Edit_BasicSSID buffer overflow
A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function EditBasicSSID of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6560?
CVE-2026-6560 has a high severity due to the potential for remote code execution through buffer overflow.
How do I fix CVE-2026-6560?
To fix CVE-2026-6560, update the H3C Magic B0 firmware to a version greater than 100R002.
What systems are affected by CVE-2026-6560?
CVE-2026-6560 affects H3C Magic B0 devices running firmware version up to and including 100R002.
What type of vulnerability is CVE-2026-6560?
CVE-2026-6560 is classified as a buffer overflow vulnerability.
Can CVE-2026-6560 be exploited remotely?
Yes, CVE-2026-6560 can be exploited remotely by manipulating parameters sent to the Edit_BasicSSID function.