CVE-2026-18812 | H3C NX15 V100R017 /api/esps esps.ipv6.wan workMode command injection

SecurityVulns

A vulnerability described as critical has been identified in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection.

This vulnerability is registered as CVE-2026-18812. It is possible to launch the attack remotely. Furthermore, an exploit is available.

The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More