What is CVE-2026-18811?
A command injection vulnerability exists in the Add function of the /api/esps file in H3C NX15 V100R017, exploitable via the esps.filter.url argument. This allows remote attackers to execute arbitrary commands on the device. Immediate patching with manufacturer-supplied updates is required.
Azərbaycanca: H3C NX15 V100R017 modelində /api/esps faylındakı Add funksiyasında `esps.filter.url` arqumenti vasitəsilə command injection zəifliyi aşkarlanıb. Bu boşluq zərərli şəxslərə cihazı uzaqdan ələ keçirməyə imkan yarada bilər. Dərhal istehsalçı tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etmək lazımdır.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: H3C
FAQ2
What vulnerability was discovered in the H3C NX15 router?
A command injection vulnerability exists in the Add function of the /api/esps file in H3C NX15 V100R017.
Which argument is used to exploit CVE-2026-18811?
The vulnerability is exploitable via the `esps.filter.url` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.