Junglewise Threat Intelligence

CVE-2026-18901: H3C NX15 dangerous routine exposure in Web API

CVE-2026-18901 · Severity: high · CVSS 7.2 · Published 2026-08-05

Technologies: H3C NX15. Vendors: H3C.

Executive brief

H3C NX15 is a network appliance used for enterprise networking and infrastructure management. The Web API component contains a vulnerability in the service.add function that exposes dangerous operations, potentially allowing remote attackers to execute unauthorized commands or escalate privileges on the affected device.

Technical details

A vulnerability exists in the service.add function of the /api/esps endpoint in the Web API component of H3C NX15 V100R017. The flaw exposes dangerous routines that can be invoked remotely. Based on the public proof-of-concept references, this appears to be part of a post-authentication remote code execution chain. The vulnerability allows remote attackers to perform unauthorized actions, potentially leading to device compromise or privilege escalation. A CVSS score of 7.2 indicates significant impact and the exploit has been publicly disclosed.

Affected products

  • H3C NX15 V100R017

Timeline

  • 2026-08-05: disclosed

References

Related threats