H3C · Nx15 · CVE-2026-18902
**Name of the Vulnerable Software and Affected Versions**
H3C NX15 version V100R017
**Description**
A command injection issue exists in the `/api/esps` file within the `esps.wan.repeater.set/repeaterproc()` function. This occurs when the `my2P4key` argument is manipulated, allowing for remote exploitation.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `/api/esps` endpoint or avoid using the `my2P4key` argument until a patch is available.