


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version …
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 22:03:03
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A command injection vulnerability has been identified in H3C NX15 V100R017, specifically in the delete function of the /api/esps endpoint. The vulnerability is triggered by manipulating the esps.apcm.version argument, allowing an attacker to inject arbitrary commands. The attack can be initiated remotely without requiring physical access to the device. A public exploit has already been disclosed and made available, increasing the risk of exploitation in the wild. The vendor was notified prior to public disclosure. This vulnerability poses a significant risk to IoT and network infrastructure devices running the affected firmware version.
Technical details
Mitigation steps:
Affected products:
H3C NX15 V100R017
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18813
https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/esps_apcm_version_delete_root_rce
https://vuldb.com/cve/CVE-2026-18813
https://vuldb.com/submit/857811
https://vuldb.com/vuln/385812
https://vuldb.com/vuln/385812/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
