


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument w…
Published:
4 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 00:03:03
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A critical command injection vulnerability has been identified in H3C NX15 V100R017 routers. The flaw resides in the function esps.ipv6.wan within the /api/esps endpoint. An attacker can manipulate the workMode argument to achieve remote command injection, potentially leading to root-level remote code execution. The attack can be launched remotely without physical access to the device. A public exploit has already been published on GitHub, increasing the risk of active exploitation. The vendor was notified prior to public disclosure. This vulnerability poses a significant risk to IoT and network infrastructure environments using affected H3C devices.
Technical details
Mitigation steps:
Affected products:
H3C NX15 V100R017
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18812
https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_ipv6_wan_set_workmode_root_rce
https://vuldb.com/cve/CVE-2026-18812
https://vuldb.com/submit/857809
https://vuldb.com/vuln/385811
https://vuldb.com/vuln/385811/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
