H3C NX15是中国H3C公司的一款提供高速无线网络连接的路由器。 H3C NX15 V100R017版本存在权限许可和访问控制问题漏洞,该漏洞源于Web API组件/api/esps文件中service.add函数暴露危险方法,可能导致攻击者远程利用该漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-18900 | 7.2 HIGH | H3C NX15 Backend RPC esps file.exec os command injection |
| CVE-2026-18902 | 7.2 HIGH | H3C NX15 esps repeaterproc command injection |
No comments yet