Impact
The vulnerability resides in the file /api/wizard/networkSetup for H3C NX15 V100R017. A manipulated request can bypass authentication, allowing an attacker to access the network setup functionality without valid credentials. This flaw can result in unrestricted changes to network configuration, leading to potential disruption, data leakage or further lateral movement within the network.
Affected Systems
Affected devices are H3C NX15 routers running firmware version V100R017. The issue originates from the /api/wizard/networkSetup endpoint and is documented under the H3C NX15 product line.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and the EPSS score is currently unavailable, implying no publicly documented exploits at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely through the exposed API, especially if network segmentation or access controls are weak.
OpenCVE Enrichment