ZeroHour

CVE-2026-3943

moderate

Command Injection in H3C ACG1000-AK230 Portal Authentication Web Interface

CVSS 4.0
5.5 medium
EPSS
39%p99
Published
()
Modified
AI analysis

H3C's ACG1000-AK230 appliance contains a command injection flaw (CWE-74/CWE-77) in the handling of the 'suffix' parameter at the web endpoint /webui/?aaa_portal_auth_local_submit, part of the device's local AAA portal (captive portal) authentication feature. A remote, unauthenticated attacker can trigger the flaw by submitting a crafted suffix value to that endpoint, since the vulnerable request requires no privileges or user interaction per the CVSS 4.0 vector. Successful exploitation lets the attacker run arbitrary operating-system commands on the appliance with the web service's privileges; the CVSS 4.0 score (5.5, medium) rates the confidentiality, integrity, and availability impact as limited, but command execution on a network gateway can pave the way to broader device compromise. All ACG1000-AK230 units running firmware up to and including the 20260227 build are affected, and the vendor (H3C) states it is investigating and remediating, with no fixed build confirmed in the available data. An exploit has been made public per the disclosure, the flaw is not yet in CISA KEV, and EPSS assigns a 39.5% probability of exploitation within 30 days (99th percentile), indicating a high near-term exploitation risk.

What to do: Inventory your environment for H3C ACG1000-AK230 appliances and check the firmware build (builds dated up to and including 20260227 are affected); as the vendor is still remediating and no fixed build is confirmed, restrict access to the /webui/ portal-authentication interface to trusted management or guest networks and block or monitor requests to /webui/?aaa_portal_auth_local_submit. Given the 39.5% EPSS and public exploit availability, prioritize applying H3C's firmware fix as soon as an advisory with a corrected build is released.

Affected
H3C ACG1000-AK230up to and including firmware build 20260227
Estimated exposure
moderate≈ low thousands of internet-exposed appliances, with a total installed base likely in the tens of thousands — H3C ACG (Application Control Gateway) appliances are widely deployed in enterprise branch and campus networks (heavily in China), and the portal-authentication web UI at /webui/ is commonly reachable on untrusted or guest-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_portal_auth_local_submit. The manipulation of the argument suffix results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor is investigating and remediating this issue.

Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.