A vulnerability classified as critical has been found in H3C NX15 V100R017. This affects the function
delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection.
This vulnerability is documented as CVE-2026-18813. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure.