Executive brief
H3C NX15 is a network appliance used for managing corporate network infrastructure. A vulnerability in the network configuration API allows attackers to bypass authentication and gain unauthorized access to system administration functions remotely, potentially enabling attackers to reconfigure network settings, disrupt operations, or pivot deeper into the network.
Technical details
This vulnerability is an authentication bypass in the /api/wizard/networkSetup endpoint of H3C NX15 V100R017. The exact root cause is not fully documented, but the flaw allows unauthenticated remote attackers to access what should be a protected administrative function. No special preconditions or user interaction is required—the API endpoint is directly reachable over the network. An attacker can manipulate requests to this endpoint to perform network configuration changes without providing valid credentials. Patches or vendor fixes were disclosed to H3C early; consult the vendor advisory for remediation details.
Affected products
- H3C NX15 V100R017
Timeline
- 2026-08-04: disclosed
- other: Vendor contacted early about disclosure