<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>NX15 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nx15/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 04 Aug 2026 22:02:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nx15/feed.xml" rel="self" type="application/rss+xml"/><item><title>Unauthenticated Access Vulnerability in H3C NX15</title><link>https://feed.craftedsignal.io/briefs/2026-08-h3c-auth-bypass/</link><pubDate>Tue, 04 Aug 2026 22:02:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-h3c-auth-bypass/</guid><description>A missing authentication vulnerability in the H3C NX15 network device firmware (CVE-2026-18810) allows unauthenticated remote attackers to access the /api/wizard/networkSetup endpoint, potentially enabling unauthorized configuration changes.</description><content:encoded><![CDATA[<p>A security vulnerability identified as CVE-2026-18810 affects H3C NX15 devices running firmware version V100R017. The vulnerability exists within the /api/wizard/networkSetup endpoint, where improper authentication handling allows remote, unauthenticated actors to interact with the device. This flaw is classified as CWE-306 (Missing Authentication for Critical Function), meaning the device fails to verify the identity of the requester before allowing access to administrative or setup functionalities. Successful exploitation can allow an attacker to bypass intended security controls and potentially reconfigure the network device remotely. This vulnerability is significant as it affects the management plane of network infrastructure equipment, providing a vector for persistent unauthorized access or further network-level exploitation if the device is internet-facing.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to reach sensitive API endpoints on H3C NX15 devices. If exploited, an attacker could alter network settings, change administrative credentials, or manipulate traffic routing policies, leading to full device compromise. Given the function of the affected API relates to network setup, the impact is high, particularly for devices deployed at the edge of corporate or branch office networks where they provide critical connectivity.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams include:</p>
<ul>
<li>Audit all internet-facing H3C NX15 devices and restrict access to the web management interface to known, trusted management subnets or via a VPN.</li>
<li>Monitor logs for unauthorized access patterns directed at the /api/wizard/networkSetup endpoint.</li>
<li>Verify device firmware versions and coordinate with H3C support to apply patches or mitigations to address CVE-2026-18810.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-18812</category><category>command-injection</category><category>network-device</category><category>cve-2026-18813</category><category>rce</category></item></channel></rss>