Junglewise Threat Intelligence

CVE-2026-18811: H3C NX15 command injection in /api/esps Add function

CVE-2026-18811 · Severity: high · CVSS 7.2 · Published 2026-08-04

Technologies: H3C NX15. Vendors: H3C.

Executive brief

H3C NX15 is a network management appliance used by enterprises to configure and monitor network devices. A flaw in its API endpoint allows remote attackers to inject arbitrary operating system commands by manipulating the esps.filter.url parameter, potentially leading to complete system compromise and unauthorized access to network infrastructure.

Technical details

The vulnerability is a command injection flaw in the Add function of the /api/esps endpoint in H3C NX15 V100R017. The vulnerability arises from insufficient input validation on the esps.filter.url argument, which is passed unsafely to a system command. The attack is remotely exploitable without authentication requirements and allows an attacker to execute arbitrary commands with the privileges of the application. Public exploit code is now available. A patch or mitigation from the vendor should be monitored.

Affected products

  • H3C NX15 V100R017

Timeline

  • 2026-08-04: disclosed

References

Related threats