---
id: CVE-2026-15479
title: A vulnerability was found in H3C NX15 V100R017
summary: >-
  A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability
  is the function change_passwd of the file /api/login/modify of the component
  Administrator Password Modification Endpoint. The manipulation of the argument
  ne…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-640
published: '2026-07-12'
updated: '2026-07-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15479'
references:
  - url: >-
      https://github.com/coconut652-7/IOT_Vul_Public/tree/main/H3C/NX15R017/pre_auth_pwd_change
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15479'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/837069'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377785'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377785/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-12T06:19:30.399Z'
epss: 0.00472
epssPercentile: 0.38225
---

## Overview

A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newPass results in weak password recovery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
