top of page
perceptive_background_267k.jpg

A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manip…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 06:00:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities

A security vulnerability has been identified in H3C NX15 V100R017, specifically in the service.add function of the /api/esps Web API endpoint. The flaw exposes a dangerous routine that can be exploited remotely without physical access to the device. A public proof-of-concept exploit has been disclosed on GitHub, increasing the risk of active exploitation. The vulnerability was responsibly disclosed to the vendor prior to public release. This issue falls under the category of exposed dangerous routines in IoT networking equipment. The affected product is a network device manufactured by H3C, a prominent networking vendor. The exploit chain reportedly achieves root-level remote code execution. The public availability of the PoC significantly elevates the risk for unpatched deployments.

Technical details

Mitigation steps:

Affected products:

H3C NX15 V100R017

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page