H3C N12 V100R005 Buffer Overflow Vulnerability in MAC Address Update Function

Vulnerability

A buffer overflow vulnerability has been identified in the H3C N12 V100R005 router model. This vulnerability arises from the MAC address update function's failure to properly verify the length of incoming data. Attackers who exploit this vulnerability can cause the device to crash or execute arbitrary commands by sending a specially crafted POST request to the device's web interface.

Impact

Exploitation of this vulnerability can lead to a denial of service, causing the device to crash, or allow for arbitrary command execution on the device.

Reproduction

To reproduce this vulnerability, send a POST request to the '/bin/webs' endpoint with a crafted MAC address that exceeds the expected length. The lack of proper length validation will trigger the buffer overflow, potentially leading to a crash or unauthorized command execution on the device.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.7
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.