PatchSiren

H3C CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH H3C CVE published 2026-08-04

CVE-2026-18811

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-04T21:16:35.730Z and has not been modified since then. The vulnerability exists in H3C NX15 V100R017, specifically in the function Add of the file /api/esps, which is susceptible to command injection via the argument esps.filter.url. The attack can be initiated remotely, and the exploit is publicly [truncated]

MEDIUM H3C CVE published 2026-07-16

CVE-2026-15907

A SQL injection vulnerability has been identified in H3C SecPath F1000-C8300 up to version 20260522. The vulnerability affects an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. By manipulating the 'subject' argument, an attacker can execute a SQL injection attack remotely. The exploit for this vulnerability has been made public and may be used by malicious actors. The vendor, H3C, was no [truncated]

MEDIUM H3C CVE published 2026-07-12

CVE-2026-15479

A vulnerability was found in H3C NX15 V100R017, affecting the function change_passwd of the file /api/login/modify in the Administrator Password Modification Endpoint. The manipulation of the argument newPass results in weak password recovery. The attack may be launched remotely. The exploit has been made public and could be used. This issue has a CVSS score of 5.5 and is considered Medium severity. Secur [truncated]