Junglewise Threat Intelligence

CVE-2026-15479: H3C NX15 weak password recovery in Administrator Password Modification Endpoint

CVE-2026-15479 · Severity: high · CVSS 7.3 · Published 2026-07-12

Technologies: H3C NX15. Vendors: H3C.

Executive brief

A security flaw in the H3C NX15 router allows unauthorized individuals to reset the administrator password. This router is typically used to provide network connectivity for homes or small offices. An attacker could exploit this to take full control of the device, potentially intercepting network traffic or disrupting internet service.

Technical details

A weak password recovery vulnerability (CWE-640) exists in the H3C NX15 V100R017 router. The flaw is located in the 'change_passwd' function within the '/api/login/modify' endpoint. By manipulating the 'newPass' argument, a remote, unauthenticated attacker can bypass intended security controls to reset the administrator password. This leads to complete administrative account takeover. Public exploit code and proof-of-concept materials have been disclosed.

Affected products

  • H3C NX15 V100R017

Timeline

  • 2026-07-12: disclosed: Vulnerability published on NVD and VulDB

References

Related threats