A vulnerability classified as critical has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection.

This vulnerability is documented as CVE-2026-18813. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure.