Junglewise Threat Intelligence

CVE-2026-18900: H3C NX15 OS command injection in Backend RPC

CVE-2026-18900 · Severity: high · CVSS 7.2 · Published 2026-08-05

Technologies: H3C NX15. Vendors: H3C.

Executive brief

H3C NX15 is a network management and control system used in enterprise environments. An OS command injection vulnerability in the Backend RPC component allows attackers to execute arbitrary operating system commands on the device. If exploited, an attacker could gain complete control of the system and compromise network infrastructure.

Technical details

The vulnerability is an OS command injection flaw in the file.exec function of the /api/esps endpoint in the Backend RPC component of H3C NX15 V100R017. The vulnerability exists due to insufficient input validation of the File parameter, which is passed unsanitized to operating system command execution. The attack is remotely accessible and exploitable after authentication. A successful exploit allows an attacker to execute arbitrary OS commands with the privileges of the affected service, potentially leading to complete system compromise. Public exploit code is available.

Affected products

  • H3C NX15 V100R017

Timeline

  • 2026-08-05: disclosed
  • other: Public exploit code made available

References

Related threats