CVE-2026-6563General

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation of the argument param leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-19); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-18: 1Mentions · 2026-04-19: 3Mentions · 2026-04-20: 1Technical Details · 2026-04-19: 204-1804-1904-20
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-181
General1
2026-04-193
Disclosure2General1
2026-04-201
General1
Full discourse5 posts
  • VulDB 🛡@vuldb
    General

    We have just added an important vulnerability affecting H3C Magic B1 (CVE-2026-6563) https://vuldb.com/vuln/358200

    Post summary

    A short note announces that CVE-2026-6563 for H3C Magic B1 has been added to a vulnerability database, but provides no further technical or operational details.

    0101090
    2.1K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🟠 CVE-2026-6563 | CVSS 8.8 🟠 CVE-2026-6574 | CVSS 7.3 🟠 CVE-2026-6569 | CVSS 7.3 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three CVE identifiers with their CVSS scores, but provides no additional technical or operational details.

    0000075
    5.6K followersView on X
  • VulDB 🛡@vuldb
    General

    Our CTI team identified a lot of activities targeting H3C Magic B1 (CVE-2026-6563) https://vuldb.com/vuln/358200/cti

    Post summary

    The CTI team notes many activities targeting H3C Magic B1 for CVE‑2026‑6563 but provides no further technical or actionable details.

    0000063
    2.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6563 A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation … https://www.cve.org/CVERecord?id=CVE-2026-6563 ----- Traducción: CVE-2026-6563 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-6563, detailing the affected element and linking to the CVE record, but provides no PoC, exploit code, or patch information.

    0000033
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6563 A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoById of the file /goform/aspForm. The manipulation … https://www.cve.org/CVERecord?id=CVE-2026-6563

    Post summary

    A vulnerability (CVE‑2026‑6563) has been disclosed for H3C Magic B1 devices, affecting the SetAPWifiorLedInfoById function; no PoC, exploit, patch, or active exploitation details are provided.

    00000177
    57.2K followersView on X

Explore more