{"schema_version":1,"title":"H3C NX15 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in H3C NX15: 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18902, was published on 5 August 2026.","url":"https://junglewise.ai/threats/technologies/nx15","json_url":"https://junglewise.ai/threats/technologies/nx15.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/nx15","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":9,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":9},"latest":[{"cve":"CVE-2026-18902","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration","title":"H3C NX15 command injection in WAN repeater configuration","severity":"high","exploited":false,"published_at":"2026-08-05T06:16:37.49+00:00","url":"https://junglewise.ai/threats/cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration"},{"cve":"CVE-2026-18901","cvss":7.2,"epss":0.0085,"slug":"cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api","title":"H3C NX15 dangerous routine exposure in Web API","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.433+00:00","url":"https://junglewise.ai/threats/cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api"},{"cve":"CVE-2026-18900","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc","title":"H3C NX15 OS command injection in Backend RPC","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.243+00:00","url":"https://junglewise.ai/threats/cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc"},{"cve":"CVE-2026-18814","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config","title":"H3C NX15 command injection in reload.reload_config","severity":"high","exploited":false,"published_at":"2026-08-04T22:17:13.75+00:00","url":"https://junglewise.ai/threats/cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config"},{"cve":"CVE-2026-18813","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18813-h3c-nx15-command-injection-in-api-esps-delete","title":"H3C NX15 command injection in /api/esps delete","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:36.053+00:00","url":"https://junglewise.ai/threats/cve-2026-18813-h3c-nx15-command-injection-in-api-esps-delete"},{"cve":"CVE-2026-18812","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18812-h3c-nx15-command-injection-in-esps-ipv6-wan","title":"H3C NX15 command injection in esps.ipv6.wan","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:35.89+00:00","url":"https://junglewise.ai/threats/cve-2026-18812-h3c-nx15-command-injection-in-esps-ipv6-wan"},{"cve":"CVE-2026-18811","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18811-h3c-nx15-command-injection-in-api-esps-add-function","title":"H3C NX15 command injection in /api/esps Add function","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:35.73+00:00","url":"https://junglewise.ai/threats/cve-2026-18811-h3c-nx15-command-injection-in-api-esps-add-function"},{"cve":"CVE-2026-18810","cvss":7.3,"epss":0.0065,"slug":"cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api","title":"H3C NX15 authentication bypass in network setup API","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:51.36+00:00","url":"https://junglewise.ai/threats/cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api"},{"cve":"CVE-2026-15479","cvss":7.3,"slug":"cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password","title":"H3C NX15 weak password recovery in Administrator Password Modification Endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T06:16:41.35+00:00","url":"https://junglewise.ai/threats/cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"H3C NX15","slug":"nx15","vendor":{"name":"H3C","slug":"h3c","url":"https://junglewise.ai/threats/vendors/h3c"},"aliases":[],"category":"firmware","homepage":"https://www.h3c.com/en/","description":"The H3C NX15 is a wireless router designed for home and small office networking.","url":"https://junglewise.ai/threats/technologies/nx15"},"most_severe":[{"cve":"CVE-2026-18810","cvss":7.3,"epss":0.0065,"slug":"cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api","title":"H3C NX15 authentication bypass in network setup API","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:51.36+00:00","url":"https://junglewise.ai/threats/cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api"},{"cve":"CVE-2026-15479","cvss":7.3,"slug":"cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password","title":"H3C NX15 weak password recovery in Administrator Password Modification Endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T06:16:41.35+00:00","url":"https://junglewise.ai/threats/cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password"},{"cve":"CVE-2026-18902","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration","title":"H3C NX15 command injection in WAN repeater configuration","severity":"high","exploited":false,"published_at":"2026-08-05T06:16:37.49+00:00","url":"https://junglewise.ai/threats/cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration"},{"cve":"CVE-2026-18900","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc","title":"H3C NX15 OS command injection in Backend RPC","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.243+00:00","url":"https://junglewise.ai/threats/cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc"},{"cve":"CVE-2026-18814","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config","title":"H3C NX15 command injection in reload.reload_config","severity":"high","exploited":false,"published_at":"2026-08-04T22:17:13.75+00:00","url":"https://junglewise.ai/threats/cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config"},{"cve":"CVE-2026-18813","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18813-h3c-nx15-command-injection-in-api-esps-delete","title":"H3C NX15 command injection in /api/esps delete","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:36.053+00:00","url":"https://junglewise.ai/threats/cve-2026-18813-h3c-nx15-command-injection-in-api-esps-delete"},{"cve":"CVE-2026-18812","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18812-h3c-nx15-command-injection-in-esps-ipv6-wan","title":"H3C NX15 command injection in esps.ipv6.wan","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:35.89+00:00","url":"https://junglewise.ai/threats/cve-2026-18812-h3c-nx15-command-injection-in-esps-ipv6-wan"},{"cve":"CVE-2026-18811","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18811-h3c-nx15-command-injection-in-api-esps-add-function","title":"H3C NX15 command injection in /api/esps Add function","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:35.73+00:00","url":"https://junglewise.ai/threats/cve-2026-18811-h3c-nx15-command-injection-in-api-esps-add-function"},{"cve":"CVE-2026-18901","cvss":7.2,"epss":0.0085,"slug":"cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api","title":"H3C NX15 dangerous routine exposure in Web API","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.433+00:00","url":"https://junglewise.ai/threats/cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}