CVE-2024-42638: h3c Magic b1st Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Affected products

  • h3c Magic b1st Firmware: version 100r012 only

Published 2024-08-16. Last modified 2026-06-17.