CVE-2026-18810
7.3 HIGHpublic exploit availablePublished 2026-08-04 · Updated 2026-08-05
AI risk analysis
- Summary
- The vulnerability allows for authentication bypass in H3C NX15 V100R017 through manipulation of an API endpoint, leading to potential unauthorized access.
- Exploitability
- Exploitation is moderately easy with remote access required and no specific user interaction needed.
- Blast radius
- If exploited, this could result in significant data compromise or system control by unauthorized users.
- Prioritized remediation
- Apply vendor patch immediately or disable the affected API endpoint until a fix is available.
auth-bypassapiremote-exploitnetwork
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-287, CWE-306
Public exploit & PoC references
All references
- https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack
- https://vuldb.com/cve/CVE-2026-18810
- https://vuldb.com/submit/857805
- https://vuldb.com/vuln/385809
- https://vuldb.com/vuln/385809/cti
- https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/api_wizard_networksetup_preauth_hijack
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.