Impact
The vulnerability resides in the esps.wan.repeater.set/repeaterproc API endpoint of H3C NX15 V100R017 firmware. By manipulating the my2P4key parameter, an attacker can inject shell commands, leading to remote code execution. This allows an attacker full control over the device from a remote session, potentially compromising the entire network.
Affected Systems
H3C NX15 routers running firmware V100R017 are affected. No other versions are specified as vulnerable, but the CPE identifier cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:* indicates that devices with this product and firmware are in scope.
Risk and Exploitability
The CVSS score of 8.6 reflects high severity, and the exploit is publicly available, though the EPSS score is not provided. The attack vector is remote, requiring only network access to the API. The vulnerability is not listed in the CISA KEV catalog, yet its high score and public availability mean the risk remains significant, especially if the device is exposed to the internet.
OpenCVE Enrichment