Executive brief
H3C NX15 is a network management appliance used in enterprise environments. A remote command injection vulnerability in the /api/esps endpoint allows attackers to execute arbitrary system commands on the device without authentication, potentially compromising network operations and data security.
Technical details
This is a command injection vulnerability in the reload.reload_config function of the /api/esps API endpoint in H3C NX15 V100R017. The vulnerability allows unauthenticated remote attackers to inject and execute arbitrary OS commands on the affected device. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation enables complete system compromise and arbitrary code execution. Patches or mitigations from the vendor should be checked and applied immediately.
Affected products
- H3C NX15 V100R017
Timeline
- 2026-08-04: disclosed