A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-8764

CVE-2026-8764: H3C Magic B3 Buffer Overflow Vulnerability

CVE-2026-8764 is a buffer overflow vulnerability in H3C Magic B3 routers affecting the UpdateWanParams function. Attackers can exploit this remotely to compromise devices. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published: May 21, 2026

CVE-2026-8764 Overview

CVE-2026-8764 is a buffer overflow vulnerability affecting H3C Magic B3 routers up to firmware version 100R002. The flaw resides in the UpdateWanParams function within /goform/aspForm, where manipulation of the param argument triggers a memory corruption condition [CWE-119]. The vulnerability is exploitable over the network and has been publicly disclosed. According to the CVE record, the vendor was contacted prior to disclosure but did not respond.

Critical Impact

Authenticated remote attackers can corrupt memory in the router's web management interface by submitting a crafted param value to UpdateWanParams, potentially compromising device confidentiality, integrity, and availability.

Affected Products

  • H3C Magic B3 router
  • Firmware versions up to 100R002
  • Web management interface endpoint /goform/aspForm

Discovery Timeline

  • 2026-05-17 - CVE-2026-8764 published to NVD
  • 2026-05-18 - Last updated in NVD database

Technical Details for CVE-2026-8764

Vulnerability Analysis

The vulnerability is classified as an Improper Restriction of Operations within the Bounds of a Memory Buffer [CWE-119]. The affected component is the UpdateWanParams handler exposed through the router's HTTP form interface at /goform/aspForm. When the handler processes the param argument, it fails to enforce length or boundary constraints on attacker-supplied input. This allows data to be written beyond the allocated buffer, corrupting adjacent memory.

Buffer overflows in embedded HTTP handlers typically permit denial of service through process crashes and, depending on memory layout and platform protections, may permit control-flow hijacking. The H3C Magic B3 is a consumer-grade router where mitigations such as stack canaries, ASLR, and non-executable memory may be incomplete or absent.

A public exploit has been disclosed through the referenced GitHub CVE Issue Tracker and VulDB Vulnerability #364389. The EPSS probability remains low at 0.038%, but public disclosure raises the practical risk to exposed devices.

Root Cause

The UpdateWanParams function copies the param query/form value into a fixed-size buffer without validating its length. Missing bounds checks on user-controlled input lead to memory corruption when oversized data is supplied. The bug is consistent with patterns seen across H3C and similar SoHo router firmware where strcpy, sprintf, or equivalent unsafe routines handle form inputs directly.

Attack Vector

The attack is performed over the network against the router's web interface. The CVSS 4.0 vector indicates high privileges are required (PR:H), meaning the attacker must hold valid credentials to the management interface. A crafted HTTP POST request to /goform/aspForm invoking UpdateWanParams with an oversized param value triggers the overflow. Routers with management interfaces exposed to untrusted networks face elevated risk.

No verified code examples are available. Refer to the VulDB CTI entry for additional technical context.

Detection Methods for CVE-2026-8764

Indicators of Compromise

  • HTTP POST requests to /goform/aspForm containing unusually long param values targeting UpdateWanParams.
  • Unexpected reboots, web interface crashes, or watchdog resets on H3C Magic B3 devices.
  • Authenticated sessions to the router web UI originating from untrusted source IP addresses.

Detection Strategies

  • Inspect web server and HTTP access logs on the router for requests to aspForm with abnormal payload sizes.
  • Deploy network IDS/IPS rules that flag HTTP requests to /goform/aspForm with param argument lengths exceeding expected boundaries.
  • Correlate device crash events with preceding HTTP traffic to the management interface.

Monitoring Recommendations

  • Forward router syslog and HTTP access logs to a centralized log platform for retention and analysis.
  • Alert on any external (WAN-side) access to the router management interface.
  • Track failed and successful administrative authentications against the router web UI for anomalous patterns.

How to Mitigate CVE-2026-8764

Immediate Actions Required

  • Disable WAN-side access to the H3C Magic B3 web management interface and restrict administration to trusted LAN segments only.
  • Rotate administrative credentials to ensure no unauthorized account holds privileges required for exploitation.
  • Place affected routers behind segmentation controls that block direct internet access to /goform/aspForm.

Patch Information

No vendor patch has been published. According to the CVE record, H3C was contacted prior to public disclosure but did not respond. Monitor the H3C security advisories page and the VulDB Vulnerability #364389 record for future updates.

Workarounds

  • Restrict HTTP/HTTPS access to the router management interface using ACLs or firewall rules permitting only specific administrative source addresses.
  • Disable remote management features on the router if enabled.
  • Consider replacing end-of-life or unsupported H3C Magic B3 devices with actively maintained hardware if no vendor fix becomes available.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeBuffer Overflow

  • Vendor/TechH3c

  • SeverityHIGH

  • CVSS Score7.3

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-119
  • Technical References
  • GitHub CVE Issue Tracker

  • VulDB Submission #811373

  • VulDB Vulnerability #364389

  • VulDB CTI for #364389
  • Related CVEs
  • CVE-2026-6560: H3C Magic B0 Buffer Overflow Vulnerability

  • CVE-2026-6581: H3C Magic B1 Buffer Overflow Vulnerability

  • CVE-2026-6563: H3C Magic B1 Buffer Overflow Vulnerability

  • CVE-2026-3943: H3C ACG1000-AK230 RCE Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English