Executive brief
H3C NX15 is a network device used to manage and configure connectivity. A command injection vulnerability in the WAN repeater configuration API allows an authenticated attacker to execute arbitrary commands remotely on the device, potentially compromising network operations and data integrity.
Technical details
This is a command injection vulnerability (CWE-78) in the esps.wan.repeater.set/repeaterproc API endpoint of the /api/esps interface. The vulnerability exists in the my2P4key parameter, which does not properly sanitize user input before passing it to system commands. An authenticated attacker with access to the device's API can inject arbitrary OS commands through this parameter to achieve remote code execution. The exploit is publicly available and proof-of-concept code has been disclosed.
Affected products
- H3C NX15 V100R017
Timeline
- 2026-08-05: disclosed
- other: Exploit is public and may be in active use
References
- https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py
- https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md