Impact
A command injection flaw exists in the reload.reload_config function of H3C NX15 V100R017, allowing an attacker to execute arbitrary shell commands on the device. The vulnerability stems from improper validation of input supplied to the API endpoint /api/esps, and is consistent with CWE-74 and CWE-77. Successful exploitation would grant an attacker full control over the affected chassis, enabling lateral movement, data exfiltration, or service disruption.
Affected Systems
The flaw targets H3C NX15 routers running firmware V100R017. No other product versions are verified to be affected; only the listed version is confirmed.
Risk and Exploitability
The CVSS score is 8.6, indicating a high severity impact. EPSS is not available, so the precise probability of exploitation remains unclear, but a public exploit has been released. The vulnerability is not yet listed in the CISA KEV catalog, yet its accessibility via a remote API and the availability of an exploit mean that an attacker can abuse it with remote access to the management interface.
OpenCVE Enrichment