Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-18814 โ€” AI Deep Analysis Summary

CVSS 7.2 ยท High

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: The `reload_config` interface of the H3C NX15 router contains a **command injection** vulnerability.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ› ๏ธ **Defect Point**: The `reload.reload_config` function in the `/api/esps` file is handled improperly.โ€ฆ

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Affected Products**: H3C NX15 series routers. ๐Ÿ“Œ **Specific Version**: V100R017. โš ๏ธ Other versions require verification, but this version is high-risk.

Q4What can hackers do? (Privileges/Data)

๐Ÿ‘‘ **Privileges**: Injected commands are usually executed with high privileges (e.g., root).โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”‘ **Threshold**: Requires **authentication** (PR:H). โš™๏ธ **Configuration**: No user interaction required (UI:N), network reachability is sufficient (AV:N). ๐Ÿ“‰ Difficulty: Low (AC:L).

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ’ฃ **Exp**: **Public exploitation code available**! ๐Ÿ”— Refer to the GitHub repository `IOT_Vul_Public`.โ€ฆ

Q7How to self-check? (Features/Scanning)

๐Ÿ”Ž **Self-Check**: Scan the `/api/esps` interface for the presence of the `reload_config` parameter. ๐Ÿงช **Testing**: Try injecting simple commands (e.g., `;id`) to see if there is a response.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿ›ก๏ธ **Patch**: The vendor contacted and fixed the issue prior to disclosure. โœ… **Recommendation**: Immediately contact H3C to obtain a security patch for V100R017 or upgrade the firmware.

Q9What if no patch? (Workaround)

๐Ÿšง **Temporary Mitigation**: If an upgrade is not possible, **disable** external access related to `/api/esps`. ๐Ÿ”’ Configure ACLs to restrict access to the API interface to internal management IPs only.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Priority**: **Very High** (CVSS 9.8). ๐Ÿ“ข **Action**: Immediately isolate affected devices and prioritize patching. Exp is public; do not wait!