What is CVE-2026-18901?
This vulnerability affects the H3C NX15 router running version V100R017 and resides in the `service.add` function within the `/api/esps` file of the Web API component. The flaw allows for the exposure of dangerous routines and can be exploited remotely. It is strongly recommended to patch the affected devices with a security update from the vendor or restrict access to the device's internet-facing interfaces.
Azərbaycanca: Bu zəiflik H3C NX15 marşrutlaşdırıcısının V100R017 versiyasında aşkarlanıb və cihazın Web API komponentində yerləşən `/api/esps` faylındakı `service.add` funksiyasına təsir edir. Uzaqdan istismar mümkün olan bu boşluq təhlükəli rutinlərin ifşa olunmasına gətirib çıxarır. Təsirə məruz qalmış cihazların dərhal istehsalçı tərəfindən təqdim olunan təhlükəsizlik yeniləməsi ilə patç edilməsi, mümkün olmadıqda isə cihazın internetə açıq interfeyslərinin məhdudlaşdırılması tövsiyə olunur.
Related CVEs
link basis: shared vendor: H3C
FAQ2
Which function does CVE-2026-18901 affect?
This vulnerability affects the `service.add` function within the `/api/esps` file of the Web API component on the H3C NX15 router.
What is recommended to mitigate CVE-2026-18901?
It is recommended to patch the affected devices with a security update from the vendor or restrict access to the device's internet-facing interfaces.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.