CVE-2026-6581General

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-19); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-19: 1Mentions · 2026-04-20: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-28: 104-1904-2004-28
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-191
General1
2026-04-201
Disclosure1
2026-04-281
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2026-6581 (CVSS 8.8) H3C Magic B1 routers ≤100R004 vulnerable to remote buffer overflow in SetMobileAPInfoById function. Exploit is PUBLIC. Vendor unresponsive. Patch immediately or isolate affected devices. #CVE #PatchNow https://t.co/7zttFWMovF

    Post summary

    The tweet announces CVE-2026-6581, highlighting a buffer overflow vulnerability in H3C Magic B1 routers and urging immediate patching or isolation, while noting the exploit is publicly available and the vendor is unresponsive.

    0000061
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6581 A vulnerability was detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function SetMobileAPInfoById of the file /goform/aspForm. Performing a… https://www.cve.org/CVERecord?id=CVE-2026-6581

    Post summary

    CVE‑2026‑6581 has been identified in H3C Magic B1 devices, impacting the SetMobileAPInfoById function, but no PoC, exploit, active use, patch, or detailed technical classification has been provided.

    00000143
    57.2K followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in H3C Magic B1 (CVE-2026-6581) https://vuldb.com/vuln/358216

    Post summary

    A new vulnerability (CVE-2026-6581) in H3C Magic B1 is announced as having elevated criticality, but the post lacks details on exploitation, tooling, or patch information.

    0000083
    2.1K followersView on X

Explore more