Description
A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
Published: 2026-08-04
Score: 8.6 High
EPSS: 2.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in H3C NX15 V100R017 allows an attacker to manipulate the workMode argument to the esps.ipv6.wan API, resulting in command injection that can be executed remotely. The vulnerability is known to be exploitable and has been published, meaning attackers can execute arbitrary shell commands on the device.

Affected Systems

The vulnerability affects H3C NX15 routers running firmware V100R017. The affected component is the esps.ipv6.wan function in the /api/esps endpoint. While no other affected versions are listed, any device running the same firmware build is likely vulnerable.

Risk and Exploitability

The CVSS score of 8.6 reflects high severity. EPSS score of 2% indicates a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can inject and run commands remotely via the network, potentially taking full control of the device if the API is reachable from external hosts.

Generated by OpenCVE AI on August 5, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch for NX15 V100R017 as soon as it is released.
  • Restrict external network traffic to the /api/esps endpoint using firewall rules or VLAN segmentation.
  • Implement input validation to reject or sanitize the workMode parameter, ensuring that only allowed values are accepted.

Generated by OpenCVE AI on August 5, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
Title H3C NX15 esps esps.ipv6.wan command injection
First Time appeared H3c
H3c nx15
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:*
Vendors & Products H3c
H3c nx15
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-05T18:22:50.024Z

Reserved: 2026-08-04T12:46:10.721Z

Link: CVE-2026-18812

cve-icon Vulnrichment

Updated: 2026-08-05T18:19:19.545Z

cve-icon NVD

Status : Deferred

Published: 2026-08-04T21:16:35.890

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T14:45:16Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')