Executive brief
H3C NX15 is a network management appliance used by enterprises to configure and monitor network devices. A flaw in its API endpoint allows remote attackers to inject arbitrary operating system commands by manipulating the esps.filter.url parameter, potentially leading to complete system compromise and unauthorized access to network infrastructure.
Technical details
The vulnerability is a command injection flaw in the Add function of the /api/esps endpoint in H3C NX15 V100R017. The vulnerability arises from insufficient input validation on the esps.filter.url argument, which is passed unsafely to a system command. The attack is remotely exploitable without authentication requirements and allows an attacker to execute arbitrary commands with the privileges of the application. Public exploit code is now available. A patch or mitigation from the vendor should be monitored.
Affected products
- H3C NX15 V100R017
Timeline
- 2026-08-04: disclosed