top of page
perceptive_background_267k.jpg

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation o…

Published:

4 augustus 2026 om 22:00:00

Alert date:

5 augustus 2026 om 06:00:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities

A critical OS command injection vulnerability has been identified in H3C NX15 V100R017. The flaw exists in the file.exec function within the /api/esps endpoint of the Backend RPC component. An attacker can manipulate the 'File' argument to inject arbitrary OS commands remotely. The vulnerability can be exploited without physical access, making it a remote attack vector. A public proof-of-concept exploit has already been released on GitHub, increasing the risk of active exploitation. The vendor was notified prior to public disclosure. The vulnerability is classified as high severity given its remote exploitability and public exploit availability. It affects IoT/networking hardware manufactured by H3C.

Technical details

Mitigation steps:

Affected products:

H3C NX15 V100R017

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page