AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18814

HIGH · CVSS 7.2 EPSS 2.71% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the reload.reload_config function of the H3C NX15 V100R017, allowing remote attackers to execute arbitrary commands on the affected system. This high-severity flaw poses significant risks to the integrity and confidentiality of the device, making it critical for organizations using this product to prioritize patching or mitigating the vulnerability. Immediate action is advised for network administrators and security teams managing H3C devices to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18814
Severity
HIGH
CVSS
7.2
EPSS
2.71%

Original NVD Description

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.