Impact
A weakness has been identified in the H3C NX15 V100R017 firmware that allows an attacker to perform OS command injection via the file.exec function within the Backend RPC interface at /api/esps. The flaw permits arbitrary execution of OS commands, potentially enabling full system compromise. This attack is a classic command‑injection vulnerability classified as CWE-77 and CWE-78, and its CVSS score of 8.6 indicates high severity. The exploit has been publicly released, suggesting that attackers could readily deploy it against affected devices.
Affected Systems
The affected vendor is H3C, product NX15. The specific model or release affected is version V100R017 of the NX15 firmware. No other versions or sub‑products are listed as affected, and the vulnerability impacts the Backend RPC service that handles file.exec calls. System administrators managing H3C NX15 devices running this firmware should assess whether their devices expose the /api/esps endpoint to potential attackers.
Risk and Exploitability
The CVSS score of 8.6 reflects considerable impact if exploited, while the EPSS score is 2%, indicating a low but non‑zero exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, but public proof‑of‑concept code exists, indicating that attackers can deploy the flaw without official modification. The attack vector is inferred to be remote because the endpoint is reachable over the network, and the description explicitly allows remote initiation. The lack of an available KEV entry does not diminish the threat; the presence of public exploits demonstrates enabled exploitation risk.
OpenCVE Enrichment