Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · h3c

h3c

· 78 Critical

Total CVEs

181

Critical

78

Products

116

Search All CVEs →

181

Products (116)

magic r100 firmware28 CVEsmagic r200 firmware25 CVEsgr-1200w firmware21 CVEsmagic nx18 plus20 CVEsgr-1200w20 CVEsmagic nx18 plus firmware20 CVEsmagic r10019 CVEsmagic r300-2100m17 CVEsmagic r300-2100m firmware17 CVEsh20016 CVEsh200 firmware16 CVEsmagic r20012 CVEsmagic b1st11 CVEsb5 mini firmware11 CVEsmagic b1st firmware11 CVEsb5 mini11 CVEsseccenter smp-1114p026 CVEsn125 CVEsn12 firmware5 CVEsmagic r230 firmware2 CVEsgr2200 firmware2 CVEsgr22002 CVEsgr-1800ax firmware2 CVEsmagic nx152 CVEsmagic nx15 firmware2 CVEsgr-1800ax2 CVEsmagic r2302 CVEsgr-5200 firmware1 CVEsgr-5400ax1 CVEsgr-5400ax firmware1 CVEsgr-83001 CVEsgr-8300 firmware1 CVEsgr1100-p1 CVEsgr1100-p firmware1 CVEsgr32001 CVEsgr3200 firmware1 CVEsh3cloud os1 CVEsmagic b01 CVEsmagic b0 firmware1 CVEsmagic b11 CVEsmagic b1 firmware1 CVEsmagic b1stw1 CVEsmagic b1stw firmware1 CVEsmagic ba1500l1 CVEsmagic ba1500l firmware1 CVEsmagic be180001 CVEsmagic be18000 firmware1 CVEsmagic nx30 pro1 CVEsmagic nx30 pro firmware1 CVEsmagic nx4001 CVEsmagic nx400 firmware1 CVEsmagic r1601 CVEsmagic r160 firmware1 CVEsmagic r30101 CVEsmagic r3010 firmware1 CVEsmc102-g1 CVEsmc102-g firmware1 CVEsr30101 CVEsr3010 firmware1 CVEss5820 secblade vpn firewall module1 CVEss7500e secblade vpn firewall module1 CVEss9500e secblade vpn firewall module1 CVEssecbladefw1 CVEssecpath1000fe1 CVEssecpath f100-c-g31 CVEssecpath f100-c-g3 firmware1 CVEssecpath f500-6gw1 CVEssecpath f500-6gw firmware1 CVEssecpath f50101 CVEssecpath f5010 firmware1 CVEssecpath f50201 CVEssecpath f5020 firmware1 CVEssecpath f50301 CVEssecpath f5030-d1 CVEssecpath f5030-d firmware1 CVEssecpath f5030 firmware1 CVEssecpath f50401 CVEssecpath f5040 firmware1 CVEssecpath f50601 CVEssecpath f5060-d1 CVEssecpath f5060-d firmware1 CVEssecpath f5060 firmware1 CVEssecpath f50801 CVEssecpath f5080-d1 CVEssecpath f5080-d firmware1 CVEssecpath f5080 firmware1 CVEssr66 gigabit firewall module1 CVEssr88 firewall processing module1 CVEsa210-g1 CVEsssl vpn1 CVEsa210-g firmware1 CVEser2100n1 CVEser2100n firmware1 CVEser2200g21 CVEser2200g2 firmware1 CVEser3200g21 CVEser3200g2 firmware1 CVEser3260g21 CVEser3260g2 firmware1 CVEser5100g21 CVEser5100g2 firmware1 CVEser5200g21 CVEser5200g2 firmware1 CVEser6300g21 CVEser6300g2 firmware1 CVEsf1000-e vpn firewall1 CVEsgr-1100-p1 CVEsgr-1100-p firmware1 CVEsgr-1108-p1 CVEsgr-1108-p firmware1 CVEsgr-120w1 CVEsgr-22001 CVEsgr-2200 firmware1 CVEsgr-32001 CVEsgr-3200 firmware1 CVEsgr-52001 CVEs

Recent Vulnerabilities

View all 181
CVE-2026-3701HIGH 8.8

A security vulnerability has been detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function Edit_BasicSSID_5G of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-60262CRITICAL 9.8

An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a misconfiguration vulnerability about vsftpd. Through this vulnerability, all files uploaded anonymously via the FTP protocol is automatically owned by the root user and remote attackers could gain root-level control over the devices.

CVE-2025-14015HIGH 8.8

A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /goform/aspForm. This manipulation of the argument param causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-57295HIGH 8.0

H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with network access can exploit these credentials to gain unauthorized root-level access to the device via the administrative interface or other network services, potentially leading to privilege escalation, information disclosure, or arbitrary code execution.

CVE-2025-44653HIGH 7.5

In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected.

CVE-2025-5162MEDIUM 6.3

A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this issue is some unknown functionality of the file /safeEvent/importFile/. The manipulation of the argument logGeneralFile/logGeneralFile_2 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5161MEDIUM 4.3

A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function operationDailyOut of the file /safeEvent/download. The manipulation of the argument filename leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5160MEDIUM 4.3

A vulnerability classified as problematic has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected is the function Download of the file /packetCaptureStrategy/download. The manipulation of the argument Name leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5159MEDIUM 4.3

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue affects the function Download of the file /cfgFile/1/download. The manipulation of the argument Name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5158MEDIUM 4.3

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulnerability affects the function downloadSoftware of the file /cfgFile/downloadSoftware. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5157MEDIUM 4.3

A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of the file /cfgFile/fileContent. The manipulation of the argument filePath leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-5156HIGH 8.8

A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical. Affected by this issue is the function EditWlanMacList of the file /routing/goform/aspForm. The manipulation of the argument param leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-3546HIGH 8.0

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack can only be done within the local network. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

CVE-2024-57473CRITICAL 9.8

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

CVE-2024-57482CRITICAL 9.8

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

CVE-2024-57480CRITICAL 9.8

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

CVE-2024-57479CRITICAL 9.8

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

CVE-2024-57471CRITICAL 9.8

H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands by sending a POST request to /bin/webs.

CVE-2024-52765CRITICAL 9.8

H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.

CVE-2024-42639CRITICAL 9.8

H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.

CVE-2024-42638CRITICAL 9.8

H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

CVE-2024-42637CRITICAL 9.8

H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

CVE-2024-38903MEDIUM 4.1

H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.

CVE-2024-38902CRITICAL 9.8

H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

CVE-2023-5142LOW 3.7

A vulnerability classified as problematic was found in H3C GR-1100-P, GR-1108-P, GR-1200W, GR-1800AX, GR-2200, GR-3200, GR-5200, GR-8300, ER2100n, ER2200G2, ER3200G2, ER3260G2, ER5100G2, ER5200G2 and ER6300G2 up to 20230908. This vulnerability affects unknown code of the file /userLogin.asp of the component Config File Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. VDB-240238 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.