What is CVE-2026-18812?
A command injection vulnerability has been identified in the esps.ipv6.wan function within the /api/esps file of the H3C NX15 V100R017 router. This flaw allows remote attackers to execute arbitrary commands by manipulating the workMode argument. Updating the device firmware or applying the manufacturer’s security patch is strongly recommended.
Azərbaycanca: H3C NX15 V100R017 routerində /api/esps faylında yerləşən esps.ipv6.wan funksiyasında əmr inyeksiyası (command injection) zəifliyi aşkar edilib. Uzaqdan istismar edilə bilən bu boşluq vasitəsilə təcavüzkar ixtiyari əmrlər icra edə bilər. Cihazın proqram təminatını yeniləmək və ya istehsalçının təqdim edəcəyi təhlükəsizlik yamasını tətbiq etmək məsləhət görülür.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: H3C
FAQ2
In which device was the CVE-2026-18812 vulnerability discovered?
This command injection vulnerability was discovered in the H3C NX15 V100R017 router.
What should be done to mitigate CVE-2026-18812?
It is recommended to update the device firmware or apply the security patch provided by the manufacturer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.