H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different usernames to the loginsubmit.cgi endpoint and analyze response messages to distinguish between existing and non-existing accounts.
H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.