Impact
A flaw in H3C NX15 V100R017 allows an attacker to manipulate the workMode argument to the esps.ipv6.wan API, resulting in command injection that can be executed remotely. The vulnerability is known to be exploitable and has been published, meaning attackers can execute arbitrary shell commands on the device.
Affected Systems
The vulnerability affects H3C NX15 routers running firmware V100R017. The affected component is the esps.ipv6.wan function in the /api/esps endpoint. While no other affected versions are listed, any device running the same firmware build is likely vulnerable.
Risk and Exploitability
The CVSS score of 8.6 reflects high severity. EPSS is not available, indicating no current statistical data on exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. Attackers can inject and run commands remotely via the network, potentially taking full control of the device if the API is reachable from external hosts.
OpenCVE Enrichment