CVE-2026-9393: H3C Magic B0 aspForm Edit_BasicSSID_5G buffer overflow
A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function EditBasicSSID5G of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable remote/web-based administration or otherwise disable access to the /goform/aspForm endpoint (including the Edit_BasicSSID_5G function) until a vendor patch is available.
H3C Magic B0 web administration (/goform/aspForm) remote_web_admin = disabled - Compensating control
Restrict access to the device management interface and the /goform/aspForm endpoint to trusted IP addresses using firewall rules or ACLs; block access from the WAN/internet.
- Compensating control
Deploy network-level protections (WAF/IPS) to detect and block malicious or malformed requests targeting /goform/aspForm (Edit_BasicSSID_5G) while a vendor fix is not available.
- Operational
Monitor logs and network traffic for exploitation attempts against /goform/aspForm, and if compromise is suspected isolate the affected device, perform investigation/forensics, and replace or rebuild the device as needed. Apply any vendor updates when they become available.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9393?
The severity of CVE-2026-9393 is rated as high with a score of 8.8.
How do I fix CVE-2026-9393?
To fix CVE-2026-9393, ensure you update your H3C Magic B0 device to the latest firmware version that addresses this vulnerability.
What is the impact of CVE-2026-9393?
CVE-2026-9393 allows for remote exploitation through buffer overflow, which may lead to data corruption and unauthorized access.
Who is affected by CVE-2026-9393?
All users of H3C Magic B0 devices running versions up to 100R002 are affected by CVE-2026-9393.
Can CVE-2026-9393 be exploited remotely?
Yes, CVE-2026-9393 can be exploited remotely due to its nature of allowing manipulation of arguments.