Junglewise Threat Intelligence

CVE-2026-18812: H3C NX15 command injection in esps.ipv6.wan

CVE-2026-18812 · Severity: high · CVSS 7.2 · Published 2026-08-04

Technologies: H3C NX15. Vendors: H3C.

Executive brief

H3C NX15 is a networking appliance that manages IPv6 network settings. A vulnerability in the IPv6 WAN configuration function allows remote attackers to inject arbitrary commands by manipulating the workMode parameter, potentially achieving complete control over the device.

Technical details

The vulnerability is a command injection flaw in the esps.ipv6.wan function of the /api/esps endpoint in H3C NX15 V100R017. The vulnerability exists because user-supplied input in the workMode parameter is not properly sanitized before being passed to a system command execution context. An attacker can reach this endpoint remotely without authentication and inject arbitrary OS commands by crafting a malicious workMode value, leading to remote code execution with system privileges. Patches or vendor mitigations have been disclosed to the vendor.

Affected products

  • H3C NX15 V100R017

Timeline

  • 2026-08-04: disclosed: Exploit published and public

References

Related threats