Description
H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different usernames to the login_submit.cgi endpoint and analyze response messages to distinguish between existing and non-existing accounts.
Problem types
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50742 (ExploitDB-50742)
www.h3c.com (H3C Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5697.php (Zero Science Lab Disclosure (ZSL-2022-5697))
www.vulncheck.com/...ia-login-script-credential-verification (VulnCheck Advisory: H3C SSL VPN n/a Username Enumeration via Login Script Credential Verification)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.