Impact
The vulnerability resides in the service.add function of the H3C NX15 Web API at /api/esps. Manipulation of this routine exposes a dangerous operation that can be triggered remotely, allowing an attacker to execute arbitrary code on the device and achieve full system compromise. The issue maps to CWE-749, indicating kernel or system‑level code execution by an untrusted user. No clarification is provided about authentication or privilege escalation prerequisites, so attackers can exploit it over the network if the API is reachable.
Affected Systems
H3C NX15 routers running firmware V100R017 are affected. The product identifies itself as H3C NX15 and the CPE string indicates a generic model. No further sub‑model or build variations are listed.
Risk and Exploitability
The CVSS score of 8.6 denotes a high severity vulnerability with significant impact. EPSS data is not available, but a publicly disclosed exploit exists, suggesting that an attacker with network access to the device may successfully trigger remote code execution. The vendor was notified early, yet the vulnerability is not yet catalogued in CISA KEV, implying limited or delayed awareness of active use. The combination of high CVSS, known public exploit, and remote reachability warrants immediate remediation.
OpenCVE Enrichment