CVE-2026-18900 | H3C NX15 V100R017 Backend RPC /api/esps file.exec File os command injection
A vulnerability identified as critical has been detected in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection.
This vulnerability appears as CVE-2026-18900. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More