HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-18810 — A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an ...

·Source: NIST NVD

Updated:

Executive Summary

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.

Analysis

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure. CVSS Score: 7.3. Published: 2026-08-04T20:16:51.360.

Indicators of Compromise (1)

CVE (1)
CVE-2026-18810
Source Attribution

Originally published by NIST NVD on Aug 4, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-70554 — MaxSite CMS contains a PHP object injection vulnerability that allows unauthenti...

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie directly to unserialize() without validation or class allowlisting. Attackers can craft a malicious serialized PHP object payload delivered in a single HTTP request to trigger magic methods during obje

CVE-2026-70554
NIST NVD
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-18813 — A vulnerability has been found in H3C NX15 V100R017. This affects the function d...

A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure.

CVE-2026-18813
NIST NVD
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-18812 — A flaw has been found in H3C NX15 V100R017. The impacted element is the function...

A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure.

CVE-2026-18812
NIST NVD