CVE-2026-18810
CVE-2026-18810 is an authentication bypass in the H3C NX15 router's /api/wizard/networkSetup endpoint, affecting firmware V100R017. The CVSS 7.3 rating reflects that an attacker with network adjacency can reconfigure network settings remotely—but this score assumes you can actually act on it, and that's where the real problem begins. The EPSS score of 0.00383 sits well below the 0.02 threshold, which does not mean this vulnerability is safe—it likely reflects the small install base and minimal security researcher attention on this device, not the absence of exploitability. The critical question is not whether EPSS will rise, but whether a patch will ever reach deployed units. H3C's consumer SOHO hardware has no reliable automatic update mechanism, firmware versioning varies across regional batches, and this router line's support lifecycle history suggests security advisories are issued opportunistically rather than systematically. What you should do: First, determine whether this endpoint is exposed to WAN interfaces in your deployment—not all wizard endpoints are LAN-only, and ISP-provisioned units may have different exposure profiles. Second, check your deployed firmware version against V100R017 specifically; the versioning fragmentation in this device class means a vulnerability in one build does not reliably map to all variants. Third, treat this as a class-level indicator: if H3C NX15 devices exist in your fleet, the presence of a /wizard auth bypass suggests the provisioning code path was never properly retired after initial setup—a structural pattern seen across D-Link, Netgear, and TP-Link lineages, indicating this is likely not an isolated flaw. The uncomfortable reality is that responsible disclosure achieves nothing when the vendor has no binding commitment to patch. The CVE exists because disclosure happened, not because remediation followed. Your priority is network segmentation and exposure minimization—not waiting for a firmware update that may never arrive.
Reviewed through automated stages and approved by a human before publication.