What is CVE-2026-18813?
A command injection vulnerability exists in the 'delete' function of /api/esps on H3C NX15 V100R017 via the 'esps.apcm.version' argument. This remote exploit allows attackers to execute arbitrary commands on the device. As exploit details are public, users should isolate affected devices from the internet until a patch is available from the vendor.
Azərbaycanca: H3C NX15 V100R017 modelində /api/esps faylındakı delete funksiyasında 'esps.apcm.version' arqumenti vasitəsilə command injection zəifliyi aşkar edilib. Bu boşluq uzaqdan hücumçuya cihazda ixtiyari əmrlər icra etməyə imkan verir. İstismar detalı açıq olduğu üçün, cihaz istifadəçilərinə vendor tərəfindən yamaq təmin olunana qədər cihazı internetə açıq saxlamamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: H3C
FAQ2
What does the CVE-2026-18813 vulnerability allow on the H3C NX15 device?
This vulnerability allows a remote attacker to execute arbitrary commands on the device via the delete function in the /api/esps file.
What temporary measure is recommended for users affected by CVE-2026-18813?
Users should isolate affected devices from the internet until a patch is available from the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.