H3C SecPath F1000-C8300 Series Firewall SQL Injection Vulnerability in log_fw_nbc_mail_jsondata

Vulnerability

A SQL injection vulnerability has been identified in the H3C SecPath F1000-C8300 series firewall, affecting versions prior to 20260522. The issue arises in the web interface, specifically within the log_fw_nbc_mail_jsondata function. The vulnerability can be exploited remotely by injecting a UNION SELECT payload into the subject parameter, allowing attackers to access SQLite metadata, such as table names from sqlite_master.

Impact

Exploitation of this vulnerability allows for SQL injection, enabling attackers to manipulate database queries and potentially access or modify database information.

Reproduction

To reproduce this vulnerability, access the web interface of the affected firewall version and navigate to the log_fw_nbc_mail_jsondata function. Inject a payload into the subject parameter that exploits the SQL injection flaw, such as a UNION SELECT payload.

Remediation

A technical fix is planned to be released.

Added: Jul 16, 2026, 12:20 AM
Updated: Jul 16, 2026, 12:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
8.7
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.