{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18812/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-18810"},{"cvss":7.2,"id":"CVE-2026-18814"},{"cvss":7.2,"id":"CVE-2026-18811"},{"cvss":7.2,"id":"CVE-2026-18812"},{"cvss":7.2,"id":"CVE-2026-18900"},{"cvss":7.2,"id":"CVE-2026-18813"},{"cvss":7.2,"id":"CVE-2026-18901"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":[],"_cs_products":["NX15 (V100R017)","NX15"],"_cs_severities":["high"],"_cs_tags":["cve-2026-18812","command-injection","network-device","cve-2026-18813","rce"],"_cs_type":"advisory","_cs_vendors":["H3C"],"content_html":"\u003cp\u003eA security vulnerability identified as CVE-2026-18810 affects H3C NX15 devices running firmware version V100R017. The vulnerability exists within the /api/wizard/networkSetup endpoint, where improper authentication handling allows remote, unauthenticated actors to interact with the device. This flaw is classified as CWE-306 (Missing Authentication for Critical Function), meaning the device fails to verify the identity of the requester before allowing access to administrative or setup functionalities. Successful exploitation can allow an attacker to bypass intended security controls and potentially reconfigure the network device remotely. This vulnerability is significant as it affects the management plane of network infrastructure equipment, providing a vector for persistent unauthorized access or further network-level exploitation if the device is internet-facing.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to reach sensitive API endpoints on H3C NX15 devices. If exploited, an attacker could alter network settings, change administrative credentials, or manipulate traffic routing policies, leading to full device compromise. Given the function of the affected API relates to network setup, the impact is high, particularly for devices deployed at the edge of corporate or branch office networks where they provide critical connectivity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams include:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all internet-facing H3C NX15 devices and restrict access to the web management interface to known, trusted management subnets or via a VPN.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unauthorized access patterns directed at the /api/wizard/networkSetup endpoint.\u003c/li\u003e\n\u003cli\u003eVerify device firmware versions and coordinate with H3C support to apply patches or mitigations to address CVE-2026-18810.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T08:06:29Z","date_published":"2026-08-04T22:02:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-h3c-auth-bypass/","summary":"A missing authentication vulnerability in the H3C NX15 network device firmware (CVE-2026-18810) allows unauthenticated remote attackers to access the /api/wizard/networkSetup endpoint, potentially enabling unauthorized configuration changes.","title":"Unauthenticated Access Vulnerability in H3C NX15","url":"https://feed.craftedsignal.io/briefs/2026-08-h3c-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18812","version":"https://jsonfeed.org/version/1.1"}