CVE-2026-15479Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password Modification Endpoint. The manipulation of the argument newPass results in weak password recovery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-12: 1Mentions · 2026-07-13: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 107-1207-13
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-121
Disclosure1
2026-07-131
General1
Full discourse2 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    General

    CVE-2026-15479 H3C NX15 Unauthenticated password change could let attackers with network access take over router administration and control device settings Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-12/TIER_2_CVE-2026-15479.md #CyberSecurity #NetworkSecurity #VulnerabilityManagement

    Post summary

    The tweet highlights CVE‑2026‑15479, noting that an unauthenticated password‑change vulnerability could allow network attackers to take full control of H3C NX15 routers, and provides a link to a detailed analysis but no evidence of active exploitation, PoC, or patch status.

    0000039
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15479 A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administra… https://www.cve.org/CVERecord?id=CVE-2026-15479

    Post summary

    The post announces that CVE‑2026‑15479 affects H3C NX15 V100R017 by compromising the `change_passwd` function in `/api/login/modify`, providing only basic technical details without any PoC, exploit, patch or active use information.

    00000973
    57.8K followersView on X

Explore more