H3C vulnerabilities
9 CVEs tracked
In our reporting, H3C appears in the context of numerous critical vulnerabilities primarily affecting its routers, with the NX15 (V100R017) model being the most prominent. The central theme revolves around multiple command injection flaws within the `/api/esps` interface (CVE-2026-18811, CVE-2026-18812, CVE-2026-18813, CVE-2026-18814) and a missing authentication vulnerability (CVE-2026-18810), all enabling unauthenticated remote code execution. Since exploit code is publicly available, defenders must immediately focus on monitoring for suspicious requests targeting the `/api/esps` endpoint, prioritizing firmware updates, and disabling internet-facing management interfaces where possible.
Azərbaycanca: Hesabatlarımızda H3C, xüsusilə NX15 (V100R017) modeli başda olmaqla, çoxsayda marşrutlaşdırıcılarında aşkarlanmış kritik zəifliklərlə bağlı kontekstdə görünür. Əsas mövzu `/api/esps` interfeysində cəmlənmiş uzaqdan kod icrasına imkan verən çoxsaylı command injection (CVE-2026-18811, CVE-2026-18812, CVE-2026-18813, CVE-2026-18814) və bir autentifikasiyadan yayınma (CVE-2026-18810) zəifliyidir. Bu zəifliklərin istismar kodları artıq ictimaiyyətə açıq olduğu üçün müdafiəçi dərhal diqqətini `/api/esps` ünvanına gələn şübhəli sorğuların monitorinqinə, cihazları mümkün ən son firmware versiyasına yeniləməyə və mümkünsə internetə açıq idarəetmə interfeyslərini bağlamağa yönəltməlidir.
This vendor's CVEs9
This hub is built from skopnix's own reporting on H3C: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.