CVE-2026-18901: Exposed Dangerous Routine in H3C NX15
CVE-2026-18901 is a high-severity security vulnerability in H3C NX15 V100R017 affecting the Web API component. Specifically, the function service.add in the /api/esps file exposes a dangerous routine that can be manipulated remotely. The vulnerability has a CVSS 4.0 base score of 8.6, indicating a high impact. Exploit details have been publicly disclosed, but no confirmed exploits are known to be active in the wild. The vendor was notified early, but no official patch or remediation guidance is currently available.
AI Analysis
Technical Summary
This vulnerability involves an exposed dangerous routine in the service.add function of the /api/esps file within the Web API component of H3C NX15 V100R017. The flaw allows remote attackers to manipulate this routine, potentially leading to significant security impacts. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, and high impacts on confidentiality, integrity, and availability. Although the exploit has been publicly disclosed, there is no evidence of active exploitation in the wild. The vendor has been contacted but has not yet provided a remediation or patch.
Potential Impact
Successful exploitation could lead to severe compromise of the affected system's confidentiality, integrity, and availability due to the exposed dangerous routine. The vulnerability is remotely exploitable without user interaction and with low complexity, making it a significant risk if left unaddressed. However, no active exploitation has been reported so far.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround has been published by the vendor, organizations should monitor vendor communications closely for updates. Until a patch is available, consider restricting access to the affected API endpoint and applying network-level controls to limit exposure.
CVE-2026-18901: Exposed Dangerous Routine in H3C NX15
Description
CVE-2026-18901 is a high-severity security vulnerability in H3C NX15 V100R017 affecting the Web API component. Specifically, the function service.add in the /api/esps file exposes a dangerous routine that can be manipulated remotely. The vulnerability has a CVSS 4.0 base score of 8.6, indicating a high impact. Exploit details have been publicly disclosed, but no confirmed exploits are known to be active in the wild. The vendor was notified early, but no official patch or remediation guidance is currently available.
CVSS v4.0
Score 8.6high
Affected software
H3C
NX15
cpe:2.3:a:h3c:nx15:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an exposed dangerous routine in the service.add function of the /api/esps file within the Web API component of H3C NX15 V100R017. The flaw allows remote attackers to manipulate this routine, potentially leading to significant security impacts. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required, no user interaction, and high impacts on confidentiality, integrity, and availability. Although the exploit has been publicly disclosed, there is no evidence of active exploitation in the wild. The vendor has been contacted but has not yet provided a remediation or patch.
Potential Impact
Successful exploitation could lead to severe compromise of the affected system's confidentiality, integrity, and availability due to the exposed dangerous routine. The vulnerability is remotely exploitable without user interaction and with low complexity, making it a significant risk if left unaddressed. However, no active exploitation has been reported so far.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or workaround has been published by the vendor, organizations should monitor vendor communications closely for updates. Until a patch is available, consider restricting access to the affected API endpoint and applying network-level controls to limit exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-04T20:05:16.930Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a72bb88bf8831d53939ad7e
Added to database: 08/05/2026, 04:26:48 UTC
Last enriched: 08/12/2026, 15:47:26 UTC
Last updated: 09/19/2026, 22:01:32 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.