CVE-2026-18902
7.2 HIGHpublic exploit availablePublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- This vulnerability allows command injection through manipulation of the my2P4key argument in the esps.wan.repeater.set/repeaterproc function, enabling remote code execution.
- Exploitability
- Exploitation requires access to the API and control over the my2P4key parameter; public exploits exist.
- Blast radius
- If exploited, this could lead to full compromise of affected H3C NX15 devices, including potential data theft or system manipulation.
- Prioritized remediation
- Update to the latest version of H3C NX15 V100R017 or apply vendor-provided patches immediately.
rceapicommand-injectionremote-exploit
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-74, CWE-77
Public exploit & PoC references
- https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py
- https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md
All references
- https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/poc/postauth_esps_wan_repeater_repeaterproc_rce.py
- https://github.com/coconut652-7/IOT_Vul_Public/blob/main/H3C/NX15R017/esps.wan.repeater.set-repeaterproc/report/postauth_esps_wan_repeater_repeaterproc_rce_report.md
- https://vuldb.com/cve/CVE-2026-18902
- https://vuldb.com/submit/857833
- https://vuldb.com/vuln/385936
- https://vuldb.com/vuln/385936/cti
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.