top of page
perceptive_background_267k.jpg

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, and H…

Published:

3 augustus 2026 om 22:00:00

Alert date:

4 augustus 2026 om 21:03:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities

Multiple H3C network devices are affected by critical command injection vulnerabilities in the /api/esps request handler. Affected models include H3C Magic BE18000, NX400, Magic NX30 Pro, Magic R3010, Magic NX15, Magic R1510, and NE36 Pro. The vulnerabilities exist across several object interfaces and methods including esps.dhcpd.vlan, esps.filter.url, esps.apcm.version, esps.swcm.version, and esps.system.ntp. Attacker-controlled parameters are passed into shell expressions executed via eval without proper validation. A remote attacker can exploit these flaws to execute arbitrary commands as root, gaining complete control of the affected device. No authentication requirements are mentioned, making this a significant remote code execution risk for network infrastructure.

Technical details

Mitigation steps:

Affected products:

H3C Magic BE18000 V200R007
H3C NX400 V100R015
H3C Magic NX30 Pro V100R0011
H3C Magic R3010 V100R009
H3C Magic NX15 V100R017
H3C Magic R1510 V100R016
H3C NE36 Pro V100R002

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page