H3C NX15是中国H3C公司的一款提供高速无线网络连接的路由器。 H3C NX15 V100R017版本存在命令注入漏洞,该漏洞源于组件Backend RPC中文件/api/esps的file.exec函数对参数File的操作,可能导致操作系统命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-18901 | 7.2 HIGH | H3C NX15 Web API esps service.add routine |
| CVE-2026-18902 | 7.2 HIGH | H3C NX15 esps repeaterproc command injection |
No comments yet