CVE-2026-3701 is a high-severity buffer overflow vulnerability (CVSS 8.8) affecting H3C Magic B1 routers up to version 100R004. Specifically, the Edit_BasicSSID_5G function in /goform/aspForm is susceptible to remote manipulation of the 'param' argument. This flaw allows for high impact to confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, and no official patches or exploit modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 100r004CPE matchmatch criteria | cpe:2.3:o:h3c:magic_b1_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.