CVE-2026-18901: H3C NX15 Web API esps service.add routine
A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18901?
The severity of CVE-2026-18901 is high with a score of 7.2.
How do I fix CVE-2026-18901?
To fix CVE-2026-18901, apply the latest security patch for H3C NX15 V100R017 that addresses the vulnerability in the Web API esps service.add routine.
What impact does CVE-2026-18901 have on my system?
CVE-2026-18901 can lead to exposure of dangerous routines, allowing an attacker to manipulate the system remotely.
Can CVE-2026-18901 be exploited remotely?
Yes, CVE-2026-18901 can be exploited remotely, making it critical to secure affected systems.
What component is affected by CVE-2026-18901?
CVE-2026-18901 affects the service.add function in the Web API of H3C NX15 V100R017.