{"id":"CVE-2026-18902","published":"2026-08-05T06:16:37.490","lastModified":"2026-08-05T14:17:04.910","description":"A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.","cvssScore":7.2,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-74","CWE-77"],"vendors":[],"products":[],"references":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py","tags":[]},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-18902","tags":[]},{"url":"https://vuldb.com/submit/857833","tags":[]},{"url":"https://vuldb.com/vuln/385936","tags":[]},{"url":"https://vuldb.com/vuln/385936/cti","tags":[]}],"exploitRefs":[{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py","tags":[]},{"url":"https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md","tags":[]}],"hasPoc":true,"ai":{"summary":"This vulnerability allows command injection through manipulation of the my2P4key argument in the esps.wan.repeater.set/repeaterproc function, enabling remote code execution.","exploitability":"Exploitation requires access to the API and control over the my2P4key parameter; public exploits exist.","blast_radius":"If exploited, this could lead to full compromise of affected H3C NX15 devices, including potential data theft or system manipulation.","remediation":"Update to the latest version of H3C NX15 V100R017 or apply vendor-provided patches immediately.","tags":["rce","api","command-injection","remote-exploit"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:02:23.726Z"}}