Impact
The vulnerability appears in the esps.wan.repeater.set/repeaterproc API endpoint of the H3C NX15 router firmware V100R017. A crafted value for the my2P4key parameter allows an attacker to trigger shell command execution, effectively giving the attacker remote code execution capability on the device. The flaw is a classic command injection flaw, mapped to CWE-74 and CWE-77. The impact is the full compromise of the device and any networks to which it is connected.
Affected Systems
H3C NX15 routers running firmware version V100R017 are listed as affected. No other firmware releases or product variants are mentioned in the available data, so devices with that exact firmware should be considered vulnerable.
Risk and Exploitability
The CVSS score of 8.6 signifies high severity. An EPSS score of 2 % indicates that, while the probability is not trivial, the exploit is considered plausible in the wild. The vulnerability is not in the CISA KEV catalog. Because the attack is remote and only requires network access to the vulnerable API, any device exposed to the internet represents a significant risk. The public exploitation scripts documented in the references confirm that the flaw can be leveraged immediately once the device is reachable.
OpenCVE Enrichment