Junglewise Threat Intelligence

CVE-2026-18813: H3C NX15 command injection in /api/esps delete

CVE-2026-18813 · Severity: high · CVSS 7.2 · Published 2026-08-04

Technologies: H3C NX15. Vendors: H3C.

Executive brief

H3C NX15 is a network management and control appliance used in enterprise environments. A command injection vulnerability in the /api/esps API endpoint allows remote attackers to execute arbitrary system commands by manipulating the esps.apcm.version parameter, potentially leading to full system compromise.

Technical details

This is a command injection vulnerability in the delete function of the /api/esps endpoint in H3C NX15 V100R017. The vulnerability exists in the handling of the esps.apcm.version argument, where user-supplied input is not properly sanitized before being processed. An attacker can craft a malicious request with shell metacharacters in the version parameter to execute arbitrary commands on the device. The attack is remotely exploitable without authentication requirements, and exploitation details have been publicly disclosed. Patches or vendor remediation status should be verified directly with H3C.

Affected products

  • H3C NX15 V100R017

Timeline

  • 2026-08-04: disclosed: Publicly disclosed vulnerability
  • 2026-08: other: Vendor contacted early about disclosure

References

Related threats