H3C manufactures networking and security appliances widely deployed in enterprise and service-provider environments, with a vulnerability footprint concentrated in firmware for its Magic routing and GR gateway product lines. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting memory-safety and access-control defects that can grant direct device compromise in edge-network positions. The exposure recurs through weakness classes including out-of-bounds writes, classic buffer overflows, path traversal, and OS command injection, which are endemic to firmware codebases and particularly dangerous when embedded in internet-facing or perimeter devices. Defenders should prioritize firmware inventory and update cadence for affected appliances, as the critical-severity tendency creates significant risk even where patch velocity is moderate; live exploitation counts and current severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by H3c over time
Signals from CVEs in this vendor scope (181 CVEs).
181 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60262CRITICAL An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vuln | Jan 6, 2026 | 9.8 | 35 | NO | NO |
CVE-2022-34607CRITICAL H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp. | Jul 20, 2022 | 9.8 | 35 | NO | NO |
CVE-2025-14015CRITICAL A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes | Dec 4, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-37070CRITICAL H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList. | Aug 25, 2022 | 9.8 | 34 | NO | NO |
CVE-2023-33629HIGH H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm. | May 31, 2023 | 7.2 | 33 | NO | YES |
CVE-2024-57482CRITICAL H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit | Jan 14, 2025 | 9.8 | 32 | NO | NO |
CVE-2024-57480CRITICAL H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerabi | Jan 14, 2025 | 9.8 | 32 | NO | NO |
CVE-2024-57479CRITICAL H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnera | Jan 14, 2025 | 9.8 | 32 | NO | NO |
CVE-2024-57471CRITICAL H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploi | Jan 14, 2025 | 9.8 | 32 | NO | NO |
CVE-2022-34598CRITICAL The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands. | Jul 6, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (181 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by H3c.
Media articles that mention a CVE ID that affects a product developed by H3c — matched by CVE ID, not by vendor name.