A flaw has been found in H3C SecPath F1000-C8300 up to 20260522
A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. A technical fix is planned to be released.
CVSS Score
7.3
HIGH
Published
16 Jul 2026 00:16
Modified
16 Jul 2026 16:19
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Complexity
Low
Privileges
None
Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Weaknesses (CWE)
CWE-74
CWE-89
Affected Systems
No vendor data available.
External Links
KEV Status
Not in CISA KEV catalog