Executive brief
H3C NX15 is a network management and control appliance used in enterprise environments. A command injection vulnerability in the /api/esps API endpoint allows remote attackers to execute arbitrary system commands by manipulating the esps.apcm.version parameter, potentially leading to full system compromise.
Technical details
This is a command injection vulnerability in the delete function of the /api/esps endpoint in H3C NX15 V100R017. The vulnerability exists in the handling of the esps.apcm.version argument, where user-supplied input is not properly sanitized before being processed. An attacker can craft a malicious request with shell metacharacters in the version parameter to execute arbitrary commands on the device. The attack is remotely exploitable without authentication requirements, and exploitation details have been publicly disclosed. Patches or vendor remediation status should be verified directly with H3C.
Affected products
- H3C NX15 V100R017
Timeline
- 2026-08-04: disclosed: Publicly disclosed vulnerability
- 2026-08: other: Vendor contacted early about disclosure