What is CVE-2026-18814?
A command injection vulnerability was discovered in the reload.reload_config function of the /api/esps file on H3C NX15 V100R017 devices. This allows remote attacks and the exploit has been publicly disclosed. It is recommended to update the device firmware or wait for an official patch from the vendor.
Azərbaycanca: H3C NX15 V100R017 cihazında /api/esps faylındakı reload.reload_config funksiyasında əmr inyeksiyası (command injection) zəifliyi aşkarlanıb. Bu, uzaqdan hücum etməyə imkan verir və istismar kodu artıq ictimaiyyətə açıqdır. Cihazın proqram təminatını yeniləmək və ya istehsalçıdan rəsmi yamaq gözləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: H3C
FAQ2
Which version of the H3C NX15 device is affected by CVE-2026-18814?
This command injection vulnerability affects the V100R017 version of the H3C NX15 device.
Has the exploit for CVE-2026-18814 been publicly disclosed?
Yes, the exploit for this vulnerability has been publicly disclosed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.