Executive brief
H3C NX15 is a network appliance used for enterprise networking and infrastructure management. The Web API component contains a vulnerability in the service.add function that exposes dangerous operations, potentially allowing remote attackers to execute unauthorized commands or escalate privileges on the affected device.
Technical details
A vulnerability exists in the service.add function of the /api/esps endpoint in the Web API component of H3C NX15 V100R017. The flaw exposes dangerous routines that can be invoked remotely. Based on the public proof-of-concept references, this appears to be part of a post-authentication remote code execution chain. The vulnerability allows remote attackers to perform unauthorized actions, potentially leading to device compromise or privilege escalation. A CVSS score of 7.2 indicates significant impact and the exploit has been publicly disclosed.
Affected products
- H3C NX15 V100R017
Timeline
- 2026-08-05: disclosed