{"id":"CVE-2026-18901","published":"2026-08-05T05:16:49.433","lastModified":"2026-08-05T15:16:46.480","description":"A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.","cvssScore":7.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-749"],"vendors":[],"products":[],"references":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/service_add_root_rce_chain/poc/postauth_service_add_rce.py","tags":[]},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce_chain/report","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-18901","tags":[]},{"url":"https://vuldb.com/submit/857817","tags":[]},{"url":"https://vuldb.com/vuln/385935","tags":[]},{"url":"https://vuldb.com/vuln/385935/cti","tags":[]}],"exploitRefs":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/service_add_root_rce_chain/poc/postauth_service_add_rce.py","tags":[]},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce_chain/report","tags":[]}],"hasPoc":true,"ai":{"summary":"The vulnerability in H3C NX15 V100R017 allows remote attackers to manipulate service.add via the /api/esps endpoint, leading to potential high impact exposure. This matters because it can be exploited remotely without user interaction.","exploitability":"Exploitation is moderately difficult requiring knowledge of the specific API endpoint and manipulation techniques; public exploits exist.","blast_radius":"If exploited, this could lead to significant data compromise, system disruption, or remote code execution with high severity impacts.","remediation":"Apply vendor patches immediately or disable the affected /api/esps service until a fix is available.","tags":["rce","web","remote","high-impact"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:02:10.851Z"}}