No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 05 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure. | |
| Title | H3C NX15 Backend RPC esps file.exec os command injection | |
| First Time appeared |
H3c
H3c nx15 |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:* | |
| Vendors & Products |
H3c
H3c nx15 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-05T03:45:09.927Z
Reserved: 2026-08-04T20:05:12.430Z
Link: CVE-2026-18900
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T05:30:12Z