Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 3.8% | — | H3C Nx15AI | 5/8/2026 | 12/8/2026 | A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may… | |
| Aplazada | Alta (7.3) | 0.85% | — | H3C Nx15AI | 5/8/2026 | 12/8/2026 | A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Aplazada | Alta (7.3) | 3.8% | — | H3C Nx15AI | 5/8/2026 | 12/8/2026 | A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Alta (7.3) | 3.6% | — | H3C Nx15AI | 4/8/2026 | 12/8/2026 | A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure. | |
| Aplazada | Alta (7.3) | 3.6% | — | H3C Nx15AI | 4/8/2026 | 12/8/2026 | A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early… | |
| Aplazada | Alta (7.3) | 3.6% | — | H3C Nx15AI | 4/8/2026 | 12/8/2026 | A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted… | |
| Aplazada | Alta (7.3) | 3.6% | — | H3C Nx15AI | 4/8/2026 | 12/8/2026 | A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted… | |
| Aplazada | Media (6.9) | 0.65% | — | H3C Nx15AI | 4/8/2026 | 12/8/2026 | A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure. | |
| Aplazada | Crítica (9.8) | 2.3% | — | H3C Magic Be18000AIH3C Nx400AIH3C Magic Nx30 PROAIH3C Magic R3010AI+4 | 4/8/2026 | 1/10/2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affected object… | |
| Aplazada | Media (5.5) | 0.47% | — | H3C Nx15AI | 12/7/2026 | 14/7/2026 | A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newPass results in weak password recovery. The attack may be launched remotely. The… | |
| Analizada | Alta (8) | 0.41% | — | H3C Magic Nx15 Firmware | 18/9/2025 | 17/6/2026 | H3C devices running firmware version NX15V100R015 are vulnerable to unauthorized access due to insecure default credentials. The root user account has no password set, and the H3C user account uses the default password "admin," both stored in the /etc/shadow file. Attackers with network access can exploit these… | |
| Analizada | Alta (8.6) | 1.6% | — | H3C Magic Nx15 FirmwareH3C Magic Nx30 PRO FirmwareH3C Magic Nx400 FirmwareH3C Magic R3010 Firmware+1 | 14/4/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getLanguage of the component HTTP POST Request Handler.… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 14/4/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/setLanguage of the component HTTP POST Request Handler. The manipulation leads… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 14/4/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getCapabilityWeb of the component HTTP POST Request Handler. The manipulation… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI | 14/4/2025 | 17/6/2026 | A vulnerability has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014 and classified as critical. This vulnerability affects the function FCGI_WizardProtoProcess of the file /api/wizard/setsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx400AIH3C Magic R3010AI | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in H3C Magic NX15, Magic NX400 and Magic R3010 up to V100R014. This affects the function FCGI_WizardProtoProcess of the file /api/wizard/getsyncpppoecfg of the component HTTP POST Request Handler. The manipulation leads to command injection. The attack needs… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI | 13/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this issue is the function FCGI_WizardProtoProcess of the file /api/wizard/getSpecs of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI | 13/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400 and Magic R3010 up to V100R014. Affected by this vulnerability is the function FCGI_WizardProtoProcess of the file /api/wizard/getCapability of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 1.1% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 13/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected is the function FCGI_CheckStringIfContainsSemicolon of the file /api/wizard/getBasicInfo of the component HTTP POST Request Handler. The manipulation leads to… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the component HTTP POST Request Handler. The manipulation leads to… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of the component HTTP POST Request Handler. The manipulation leads… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Request Handler. The manipulation leads to command injection. The… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST Request Handler. The manipulation leads to command injection. The… | |
| Aplazada | Alta (8.6) | 1.0% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTTP POST Request Handler. The manipulation leads to command… | |
| Aplazada | Alta (8.6) | 8.3% | — | H3C Magic Nx15AIH3C Magic Nx30 PROAIH3C Magic Nx400AIH3C Magic R3010AI+1 | 25/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POST Request Handler. The manipulation leads to command injection.… |