top of page
perceptive_background_267k.jpg

A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version …

Published:

3 August 2026 at 22:00:00

Alert date:

4 August 2026 at 22:03:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities

A command injection vulnerability has been identified in H3C NX15 V100R017, specifically in the delete function of the /api/esps endpoint. The vulnerability is triggered by manipulating the esps.apcm.version argument, allowing an attacker to inject arbitrary commands. The attack can be initiated remotely without requiring physical access to the device. A public exploit has already been disclosed and made available, increasing the risk of exploitation in the wild. The vendor was notified prior to public disclosure. This vulnerability poses a significant risk to IoT and network infrastructure devices running the affected firmware version.

Technical details

Mitigation steps:

Affected products:

H3C NX15 V100R017

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page