Junglewise Threat Intelligence

CVE-2026-18902: H3C NX15 command injection in WAN repeater configuration

CVE-2026-18902 · Severity: high · CVSS 7.2 · Published 2026-08-05

Technologies: H3C NX15. Vendors: H3C.

Executive brief

H3C NX15 is a network device used to manage and configure connectivity. A command injection vulnerability in the WAN repeater configuration API allows an authenticated attacker to execute arbitrary commands remotely on the device, potentially compromising network operations and data integrity.

Technical details

This is a command injection vulnerability (CWE-78) in the esps.wan.repeater.set/repeaterproc API endpoint of the /api/esps interface. The vulnerability exists in the my2P4key parameter, which does not properly sanitize user input before passing it to system commands. An authenticated attacker with access to the device's API can inject arbitrary OS commands through this parameter to achieve remote code execution. The exploit is publicly available and proof-of-concept code has been disclosed.

Affected products

  • H3C NX15 V100R017

Timeline

  • 2026-08-05: disclosed
  • other: Exploit is public and may be in active use

References

Related threats