A missing authentication vulnerability in the H3C NX15 network device firmware (CVE-2026-18810) allows unauthenticated remote attackers to access the /api/wizard/networkSetup endpoint, potentially enabling unauthorized configuration changes.
PoC
NX15 +1
cve-2026-18812
command-injection
network-device
cve-2026-18813
rce
4r
2t
7c
4i
updated