← Back to search

CVE-2026-18902

7.2 HIGHpublic exploit available

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
This vulnerability allows command injection through manipulation of the my2P4key argument in the esps.wan.repeater.set/repeaterproc function, enabling remote code execution.
Exploitability
Exploitation requires access to the API and control over the my2P4key parameter; public exploits exist.
Blast radius
If exploited, this could lead to full compromise of affected H3C NX15 devices, including potential data theft or system manipulation.
Prioritized remediation
Update to the latest version of H3C NX15 V100R017 or apply vendor-provided patches immediately.
rceapicommand-injectionremote-exploit

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-74, CWE-77

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.