CVE-2026-18812: H3C NX15 esps esps.ipv6.wan command injection
A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18812?
CVE-2026-18812 has a severity rating of high, with a score of 7.3.
How do I fix CVE-2026-18812?
To mitigate CVE-2026-18812, update the H3C NX15 software to the latest secure version available from the vendor.
What type of vulnerability is CVE-2026-18812?
CVE-2026-18812 is classified as a command injection vulnerability.
Can CVE-2026-18812 be exploited remotely?
Yes, CVE-2026-18812 can be exploited remotely due to its nature allowing manipulation of the esps.ipv6.wan function.
What is affected in CVE-2026-18812?
The affected element in CVE-2026-18812 is the esps.ipv6.wan function located in the /api/esps file.