{"id":"CVE-2026-18810","published":"2026-08-04T20:16:51.360","lastModified":"2026-08-05T16:16:55.010","description":"A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-287","CWE-306"],"vendors":[],"products":[],"references":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-18810","tags":[]},{"url":"https://vuldb.com/submit/857805","tags":[]},{"url":"https://vuldb.com/vuln/385809","tags":[]},{"url":"https://vuldb.com/vuln/385809/cti","tags":[]},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack","tags":[]}],"exploitRefs":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack","tags":[]},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability allows for authentication bypass in H3C NX15 V100R017 through manipulation of an API endpoint, leading to potential unauthorized access.","exploitability":"Exploitation is moderately easy with remote access required and no specific user interaction needed.","blast_radius":"If exploited, this could result in significant data compromise or system control by unauthorized users.","remediation":"Apply vendor patch immediately or disable the affected API endpoint until a fix is available.","tags":["auth-bypass","api","remote-exploit","network"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:00:29.247Z"}}