{"schema_version":1,"title":"H3C vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in H3C: 0 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18902, was published on 5 August 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/h3c","json_url":"https://junglewise.ai/threats/vendors/h3c.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/h3c","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":14,"all_time":16,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":11,"last_365_days":15},"latest":[{"cve":"CVE-2026-18902","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration","title":"H3C NX15 command injection in WAN repeater configuration","severity":"high","exploited":false,"published_at":"2026-08-05T06:16:37.49+00:00","url":"https://junglewise.ai/threats/cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration"},{"cve":"CVE-2026-18901","cvss":7.2,"epss":0.0085,"slug":"cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api","title":"H3C NX15 dangerous routine exposure in Web API","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.433+00:00","url":"https://junglewise.ai/threats/cve-2026-18901-h3c-nx15-dangerous-routine-exposure-in-web-api"},{"cve":"CVE-2026-18900","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc","title":"H3C NX15 OS command injection in Backend RPC","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.243+00:00","url":"https://junglewise.ai/threats/cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc"},{"cve":"CVE-2026-18814","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config","title":"H3C NX15 command injection in reload.reload_config","severity":"high","exploited":false,"published_at":"2026-08-04T22:17:13.75+00:00","url":"https://junglewise.ai/threats/cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config"},{"cve":"CVE-2026-18813","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18813-h3c-nx15-command-injection-in-api-esps-delete","title":"H3C NX15 command injection in /api/esps delete","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:36.053+00:00","url":"https://junglewise.ai/threats/cve-2026-18813-h3c-nx15-command-injection-in-api-esps-delete"},{"cve":"CVE-2026-18812","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18812-h3c-nx15-command-injection-in-esps-ipv6-wan","title":"H3C NX15 command injection in esps.ipv6.wan","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:35.89+00:00","url":"https://junglewise.ai/threats/cve-2026-18812-h3c-nx15-command-injection-in-esps-ipv6-wan"},{"cve":"CVE-2026-18811","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18811-h3c-nx15-command-injection-in-api-esps-add-function","title":"H3C NX15 command injection in /api/esps Add function","severity":"high","exploited":false,"published_at":"2026-08-04T21:16:35.73+00:00","url":"https://junglewise.ai/threats/cve-2026-18811-h3c-nx15-command-injection-in-api-esps-add-function"},{"cve":"CVE-2026-18810","cvss":7.3,"epss":0.0065,"slug":"cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api","title":"H3C NX15 authentication bypass in network setup API","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:51.36+00:00","url":"https://junglewise.ai/threats/cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api"},{"cve":"CVE-2025-29296","cvss":9.8,"epss":0.0225,"slug":"cve-2025-29296-h3c-magic-and-nx-series-command-injection-in-api","title":"H3C Magic and NX series command injection in API","severity":"critical","exploited":false,"published_at":"2026-08-04T17:16:42.92+00:00","url":"https://junglewise.ai/threats/cve-2025-29296-h3c-magic-and-nx-series-command-injection-in-api"},{"cve":"CVE-2026-15907","cvss":7.3,"slug":"cve-2026-15907-h3c-secpath-f1000-c8300-sql-injection-in-log-fw-nbc-mail-jsondata","title":"H3C SecPath F1000-C8300 SQL injection in log_fw_nbc_mail_jsondata","severity":"high","exploited":false,"published_at":"2026-07-16T00:16:19.17+00:00","url":"https://junglewise.ai/threats/cve-2026-15907-h3c-secpath-f1000-c8300-sql-injection-in-log-fw-nbc-mail-jsondata"},{"cve":"CVE-2026-15479","cvss":7.3,"slug":"cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password","title":"H3C NX15 weak password recovery in Administrator Password Modification Endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T06:16:41.35+00:00","url":"https://junglewise.ai/threats/cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password"},{"cve":"CVE-2026-10259","cvss":8.8,"slug":"cve-2026-10259-h3c-magic-b0-stack-overflow-in-setmobileapinfobyid","title":"H3C Magic B0 stack overflow in SetMobileAPInfoById","severity":"high","exploited":false,"published_at":"2026-06-01T15:16:31.947+00:00","url":"https://junglewise.ai/threats/cve-2026-10259-h3c-magic-b0-stack-overflow-in-setmobileapinfobyid"},{"cve":"CVE-2026-9393","cvss":8.8,"epss":0.0004,"slug":"cve-2026-9393-h3c-magic-b0-buffer-overflow-in-edit-basicssid-5g","title":"H3C Magic B0 buffer overflow in Edit_BasicSSID_5G","severity":"high","exploited":false,"published_at":"2026-05-24T19:16:22.597+00:00","url":"https://junglewise.ai/threats/cve-2026-9393-h3c-magic-b0-buffer-overflow-in-edit-basicssid-5g"},{"cve":"CVE-2026-8764","cvss":7.2,"slug":"cve-2026-8764-h3c-magic-b3-buffer-overflow-in-updatewanparams","title":"H3C Magic B3 buffer overflow in UpdateWanParams","severity":"high","exploited":false,"published_at":"2026-05-17T22:16:21.463+00:00","url":"https://junglewise.ai/threats/cve-2026-8764-h3c-magic-b3-buffer-overflow-in-updatewanparams"},{"cve":"CVE-2025-63258","cvss":6.5,"epss":0.0033,"slug":"cve-2025-63258-h3c-multiple-routers-and-gateways-command-injection-in-sessionid","title":"H3C Multiple Routers and Gateways Command Injection in sessionid","severity":"medium","exploited":false,"published_at":"2025-11-18T17:16:08.183+00:00","url":"https://junglewise.ai/threats/cve-2025-63258-h3c-multiple-routers-and-gateways-command-injection-in-sessionid"},{"cve":"CVE-2025-44653","cvss":7.5,"epss":0.0052,"slug":"cve-2025-44653-h3c-gr2200-resource-exhaustion-in-bftpd-configuration","title":"H3C GR2200 resource exhaustion in bftpd configuration","severity":"high","exploited":false,"published_at":"2025-07-21T17:15:37.247+00:00","url":"https://junglewise.ai/threats/cve-2025-44653-h3c-gr2200-resource-exhaustion-in-bftpd-configuration"}],"vendor":{"hub":true,"name":"H3C","slug":"h3c","homepage":"https://www.h3c.com/en/","description":"H3C is a provider of digitalization solutions, including networking, computing, storage, and security infrastructure.","url":"https://junglewise.ai/threats/vendors/h3c"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":1,"exploited":0,"vulnerabilities":9},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2025-29296","cvss":9.8,"epss":0.0225,"slug":"cve-2025-29296-h3c-magic-and-nx-series-command-injection-in-api","title":"H3C Magic and NX series command injection in API","severity":"critical","exploited":false,"published_at":"2026-08-04T17:16:42.92+00:00","url":"https://junglewise.ai/threats/cve-2025-29296-h3c-magic-and-nx-series-command-injection-in-api"},{"cve":"CVE-2026-9393","cvss":8.8,"epss":0.0004,"slug":"cve-2026-9393-h3c-magic-b0-buffer-overflow-in-edit-basicssid-5g","title":"H3C Magic B0 buffer overflow in Edit_BasicSSID_5G","severity":"high","exploited":false,"published_at":"2026-05-24T19:16:22.597+00:00","url":"https://junglewise.ai/threats/cve-2026-9393-h3c-magic-b0-buffer-overflow-in-edit-basicssid-5g"},{"cve":"CVE-2026-10259","cvss":8.8,"slug":"cve-2026-10259-h3c-magic-b0-stack-overflow-in-setmobileapinfobyid","title":"H3C Magic B0 stack overflow in SetMobileAPInfoById","severity":"high","exploited":false,"published_at":"2026-06-01T15:16:31.947+00:00","url":"https://junglewise.ai/threats/cve-2026-10259-h3c-magic-b0-stack-overflow-in-setmobileapinfobyid"},{"cve":"CVE-2025-44653","cvss":7.5,"epss":0.0052,"slug":"cve-2025-44653-h3c-gr2200-resource-exhaustion-in-bftpd-configuration","title":"H3C GR2200 resource exhaustion in bftpd configuration","severity":"high","exploited":false,"published_at":"2025-07-21T17:15:37.247+00:00","url":"https://junglewise.ai/threats/cve-2025-44653-h3c-gr2200-resource-exhaustion-in-bftpd-configuration"},{"cve":"CVE-2026-18810","cvss":7.3,"epss":0.0065,"slug":"cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api","title":"H3C NX15 authentication bypass in network setup API","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:51.36+00:00","url":"https://junglewise.ai/threats/cve-2026-18810-h3c-nx15-authentication-bypass-in-network-setup-api"},{"cve":"CVE-2026-15907","cvss":7.3,"slug":"cve-2026-15907-h3c-secpath-f1000-c8300-sql-injection-in-log-fw-nbc-mail-jsondata","title":"H3C SecPath F1000-C8300 SQL injection in log_fw_nbc_mail_jsondata","severity":"high","exploited":false,"published_at":"2026-07-16T00:16:19.17+00:00","url":"https://junglewise.ai/threats/cve-2026-15907-h3c-secpath-f1000-c8300-sql-injection-in-log-fw-nbc-mail-jsondata"},{"cve":"CVE-2026-15479","cvss":7.3,"slug":"cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password","title":"H3C NX15 weak password recovery in Administrator Password Modification Endpoint","severity":"high","exploited":false,"published_at":"2026-07-12T06:16:41.35+00:00","url":"https://junglewise.ai/threats/cve-2026-15479-h3c-nx15-weak-password-recovery-in-administrator-password"},{"cve":"CVE-2026-18902","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration","title":"H3C NX15 command injection in WAN repeater configuration","severity":"high","exploited":false,"published_at":"2026-08-05T06:16:37.49+00:00","url":"https://junglewise.ai/threats/cve-2026-18902-h3c-nx15-command-injection-in-wan-repeater-configuration"},{"cve":"CVE-2026-18900","cvss":7.2,"epss":0.0382,"slug":"cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc","title":"H3C NX15 OS command injection in Backend RPC","severity":"high","exploited":false,"published_at":"2026-08-05T05:16:49.243+00:00","url":"https://junglewise.ai/threats/cve-2026-18900-h3c-nx15-os-command-injection-in-backend-rpc"},{"cve":"CVE-2026-18814","cvss":7.2,"epss":0.0358,"slug":"cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config","title":"H3C NX15 command injection in reload.reload_config","severity":"high","exploited":false,"published_at":"2026-08-04T22:17:13.75+00:00","url":"https://junglewise.ai/threats/cve-2026-18814-h3c-nx15-command-injection-in-reload-reload-config"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"H3C NX15","slug":"nx15","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/nx15"}]}