Executive brief
Multiple H3C network devices (routers and network appliances) contain command injection vulnerabilities in their web API request handlers. An attacker can send malicious requests to execute arbitrary commands with root privileges, gaining complete control over the affected devices. This could allow an attacker to compromise network infrastructure, access sensitive data, or disrupt network operations.
Technical details
Multiple command injection vulnerabilities exist in the /api/esps request handler across several H3C device models. Attacker-controlled parameters in esps.dhcpd.vlan, esps.filter.url, esps.apcm.version, esps.swcm.version, and esps.system.ntp interfaces are incorporated into shell expressions executed via eval without adequate validation. The vulnerabilities are reachable remotely via the web API and do not require authentication. Successful exploitation allows arbitrary command execution as root, leading to complete device compromise. Patches are expected from H3C.
Affected products
- H3C Magic BE18000 V200R007
- H3C NX400 V100R015
- H3C Magic NX30 Pro V100R0011
- H3C Magic R3010 V100R009
- H3C Magic NX15 V100R017
- H3C Magic R1510 V100R016
- H3C NE36 Pro V100R002
- H3C MC102G HM1A0 V200R010
Timeline
- 2026-08-04: disclosed