CVE-2026-18901
7.2 HIGHpublic exploit availablePublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The vulnerability in H3C NX15 V100R017 allows remote attackers to manipulate service.add via the /api/esps endpoint, leading to potential high impact exposure. This matters because it can be exploited remotely without user interaction.
- Exploitability
- Exploitation is moderately difficult requiring knowledge of the specific API endpoint and manipulation techniques; public exploits exist.
- Blast radius
- If exploited, this could lead to significant data compromise, system disruption, or remote code execution with high severity impacts.
- Prioritized remediation
- Apply vendor patches immediately or disable the affected /api/esps service until a fix is available.
rcewebremotehigh-impact
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-749
Public exploit & PoC references
All references
- https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/service_add_root_rce_chain/poc/postauth_service_add_rce.py
- https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/service_add_root_rce_chain/report
- https://vuldb.com/cve/CVE-2026-18901
- https://vuldb.com/submit/857817
- https://vuldb.com/vuln/385935
- https://vuldb.com/vuln/385935/cti
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.