Impact
The vulnerability resides in the Add function of the /api/esps endpoint on H3C NX15 routers. By manipulating the esps.filter.url parameter, an attacker can inject arbitrary shell commands, leading to remote execution of operating‑system commands on the device. The flaw, documented as command injection (CWE‑74, CWE‑77), could allow a complete compromise of the affected router, including unauthorized access, data exfiltration, or use as a pivot for further network intrusions. The CVE description does not state whether authentication is required to reach this endpoint; it only indicates that the attack can be initiated remotely.
Affected Systems
Affected systems are H3C NX15 routers with firmware version V100R017. This build is confirmed vulnerable; other firmware revisions may or may not be impacted. Administrators should verify the firmware version deployed across their fleet and assess whether the esps feature is in use.
Risk and Exploitability
The CVSS base score of 8.6 classifies this as a high‑severity vulnerability. The EPSS score of 4% suggests a moderate but still low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. The exploit is publicly available and can be triggered remotely over the network. While the CVE description does not clarify authentication requirements, it explicitly states that the attack can be initiated remotely, indicating that the endpoint is reachable from the network. The presence of a public exploit underscores the realistic risk of exploitation.
OpenCVE Enrichment