{"id":"CVE-2026-18814","published":"2026-08-04T22:17:13.750","lastModified":"2026-08-05T15:16:43.307","description":"A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.","cvssScore":7.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-74","CWE-77"],"vendors":[],"products":[],"references":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-18814","tags":[]},{"url":"https://vuldb.com/submit/857813","tags":[]},{"url":"https://vuldb.com/vuln/385813","tags":[]},{"url":"https://vuldb.com/vuln/385813/cti","tags":[]}],"exploitRefs":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability allows for command injection via the reload_config function in H3C NX15 V100R017, enabling remote code execution.","exploitability":"Exploitation is relatively easy given public exploits and requires access to the affected API endpoint.","blast_radius":"If exploited, this could lead to full control over the device, potentially affecting network security and availability.","remediation":"Apply vendor patches immediately or disable the vulnerable API function until a patch is available.","tags":["rce","api","remote","patch"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:01:56.936Z"}}