H3C · Nx15 · CVE-2026-15479
**Name of the Vulnerable Software and Affected Versions**
H3C NX15 version V100R017
**Description**
A flaw exists in the Administrator Password Modification Endpoint within the `change passwd()` function of the '/api/login/modify' endpoint. Remote manipulation of the `newPass` argument can lead to weak password recovery.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/api/login/modify' endpoint to minimize the risk of exploitation.