Description
A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
Published: 2026-08-04
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in H3C NX15 V100R017 allows an attacker to manipulate the workMode argument to the esps.ipv6.wan API, resulting in command injection that can be executed remotely. The vulnerability is known to be exploitable and has been published, meaning attackers can execute arbitrary shell commands on the device.

Affected Systems

The vulnerability affects H3C NX15 routers running firmware V100R017. The affected component is the esps.ipv6.wan function in the /api/esps endpoint. While no other affected versions are listed, any device running the same firmware build is likely vulnerable.

Risk and Exploitability

The CVSS score of 8.6 reflects high severity. EPSS is not available, indicating no current statistical data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. Attackers can inject and run commands remotely via the network, potentially taking full control of the device if the API is reachable from external hosts.

Generated by OpenCVE AI on August 4, 2026 at 21:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch for NX15 V100R017 as soon as it is released.
  • Restrict external network traffic to the /api/esps endpoint using firewall rules or VLAN segmentation.
  • Implement input validation to reject or sanitize the workMode parameter, ensuring that only allowed values are accepted.

Generated by OpenCVE AI on August 4, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
Title H3C NX15 esps esps.ipv6.wan command injection
First Time appeared H3c
H3c nx15
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:*
Vendors & Products H3c
H3c nx15
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-04T20:30:11.450Z

Reserved: 2026-08-04T12:46:10.721Z

Link: CVE-2026-18812

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:30:12Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')