Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

H3c

First CVE: Jul 28, 2014Active for: 12 yearsTotal CVEs: 181
46.1
VTI Score
High

H3C manufactures networking and security appliances widely deployed in enterprise and service-provider environments, with a vulnerability footprint concentrated in firmware for its Magic routing and GR gateway product lines. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting memory-safety and access-control defects that can grant direct device compromise in edge-network positions. The exposure recurs through weakness classes including out-of-bounds writes, classic buffer overflows, path traversal, and OS command injection, which are endemic to firmware codebases and particularly dangerous when embedded in internet-facing or perimeter devices. Defenders should prioritize firmware inventory and update cadence for affected appliances, as the critical-severity tendency creates significant risk even where patch velocity is moderate; live exploitation counts and current severity distribution are shown alongside this summary.

FAUCET AI Generated
181
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by H3c over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 2014
11 years ago
Most Recent CVE
Mar 8, 2026
138 days ago

Products(116 total)

Top CVEs

Signals from CVEs in this vendor scope (181 CVEs).

181 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-60262CRITICAL
An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vuln
Jan 6, 20269.835NONO
CVE-2022-34607CRITICAL
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp.
Jul 20, 20229.835NONO
CVE-2025-14015CRITICAL
A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes
Dec 4, 20259.834NONO
CVE-2022-37070CRITICAL
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.
Aug 25, 20229.834NONO
CVE-2023-33629HIGH
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.
May 31, 20237.233NOYES
CVE-2024-57482CRITICAL
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit
Jan 14, 20259.832NONO
CVE-2024-57480CRITICAL
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerabi
Jan 14, 20259.832NONO
CVE-2024-57479CRITICAL
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnera
Jan 14, 20259.832NONO
CVE-2024-57471CRITICAL
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploi
Jan 14, 20259.832NONO
CVE-2022-34598CRITICAL
The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.
Jul 6, 20229.832NONO
View all 181 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products181 CVEs
14%
40%
46%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local34 (18.8%)
Network144 (79.6%)
Unknown1 (0.6%)
Physical1 (0.6%)
Adjacent Network1 (0.6%)
Attack Complexity
Low180 (99.4%)
High0 (0.0%)
Unknown1 (0.6%)
User Interaction
None178 (98.3%)
Unknown1 (0.6%)
Required2 (1.1%)
Privileges Required
Low38 (21.0%)
High39 (21.5%)
None103 (56.9%)
Unknown1 (0.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (181 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.1% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by H3c.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by H3c — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For H3c's Products

View all 3 CNAs →

Top CWEs