Vendor
H3C vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 16 vulnerabilities in H3C: 0 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18902, was published on 5 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 1
- Exploited in the wild
- 0
About H3C
H3C is a provider of digitalization solutions, including networking, computing, storage, and security infrastructure.
H3C technologies
Latest H3C vulnerabilities
- CVE-2026-18902: H3C NX15 command injection in WAN repeater configurationhighCVSS 7.2EPSS 3.8%
- CVE-2026-18901: H3C NX15 dangerous routine exposure in Web APIhighCVSS 7.2EPSS 0.9%
- CVE-2026-18900: H3C NX15 OS command injection in Backend RPChighCVSS 7.2EPSS 3.8%
- CVE-2026-18814: H3C NX15 command injection in reload.reload_confighighCVSS 7.2EPSS 3.6%
- CVE-2026-18813: H3C NX15 command injection in /api/esps deletehighCVSS 7.2EPSS 3.6%
- CVE-2026-18812: H3C NX15 command injection in esps.ipv6.wanhighCVSS 7.2EPSS 3.6%
- CVE-2026-18811: H3C NX15 command injection in /api/esps Add functionhighCVSS 7.2EPSS 3.6%
- CVE-2026-18810: H3C NX15 authentication bypass in network setup APIhighCVSS 7.3EPSS 0.7%
- CVE-2025-29296: H3C Magic and NX series command injection in APIcriticalCVSS 9.8EPSS 2.3%
- CVE-2026-15907: H3C SecPath F1000-C8300 SQL injection in log_fw_nbc_mail_jsondatahighCVSS 7.3
- CVE-2026-15479: H3C NX15 weak password recovery in Administrator Password Modification EndpointhighCVSS 7.3
- CVE-2026-10259: H3C Magic B0 stack overflow in SetMobileAPInfoByIdhighCVSS 8.8
- CVE-2026-9393: H3C Magic B0 buffer overflow in Edit_BasicSSID_5GhighCVSS 8.8EPSS 0.0%
- CVE-2026-8764: H3C Magic B3 buffer overflow in UpdateWanParamshighCVSS 7.2
- CVE-2025-63258: H3C Multiple Routers and Gateways Command Injection in sessionidmediumCVSS 6.5EPSS 0.3%
- CVE-2025-44653: H3C GR2200 resource exhaustion in bftpd configurationhighCVSS 7.5EPSS 0.5%
Most severe H3C vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-29296: H3C Magic and NX series command injection in APIcriticalCVSS 9.8EPSS 2.3%
- CVE-2026-9393: H3C Magic B0 buffer overflow in Edit_BasicSSID_5GhighCVSS 8.8EPSS 0.0%
- CVE-2026-10259: H3C Magic B0 stack overflow in SetMobileAPInfoByIdhighCVSS 8.8
- CVE-2025-44653: H3C GR2200 resource exhaustion in bftpd configurationhighCVSS 7.5EPSS 0.5%
- CVE-2026-18810: H3C NX15 authentication bypass in network setup APIhighCVSS 7.3EPSS 0.7%
- CVE-2026-15907: H3C SecPath F1000-C8300 SQL injection in log_fw_nbc_mail_jsondatahighCVSS 7.3
- CVE-2026-15479: H3C NX15 weak password recovery in Administrator Password Modification EndpointhighCVSS 7.3
- CVE-2026-18902: H3C NX15 command injection in WAN repeater configurationhighCVSS 7.2EPSS 3.8%
- CVE-2026-18900: H3C NX15 OS command injection in Backend RPChighCVSS 7.2EPSS 3.8%
- CVE-2026-18814: H3C NX15 command injection in reload.reload_confighighCVSS 7.2EPSS 3.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 9 | 1 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/h3c.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "H3C vulnerabilities", https://junglewise.ai/threats/vendors/h3c, 26 September 2026.