ZeroHour

CVE-2026-73749

mass

Unauthenticated Remote Code Execution in HPE ArubaOS-CX

CVSS 3.1
9.8 critical
EPSS
<1%p40
Published
()
Modified
AI analysis

HPE has disclosed multiple flaws in a daemon of ArubaOS-CX, the operating system running on Aruba's CX enterprise switches, where the service improperly processes malformed input (CWE-284, improper access control). An unauthenticated remote attacker can trigger the issue by sending specially crafted packets to the affected service, and successful exploitation yields remote code execution with elevated privileges on the switch. The 9.8 CVSS score reflects network-based attack vectors requiring no authentication, privileges, or user interaction, with high impact on confidentiality, integrity, and availability. Organizations running ArubaOS-CX switches are affected; the specific vulnerable and fixed firmware versions are not stated in the available data and must be taken from HPE's advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.5% chance of exploitation in the next 30 days, indicating no known exploitation at this time.

What to do: Monitor HPE's security advisory for the list of affected AOS-CX releases and fixed firmware, then prioritize patching switches whose management services are reachable from untrusted networks. Until fixed builds are available, reduce exposure by placing switch management on an out-of-band management network or restricting the service with ACLs or firewall rules. Although no public PoC or in-the-wild exploitation is known, the unauthenticated nature and critical severity on core network infrastructure warrant prompt patching once firmware is published.

Affected
HPE ArubaOS-CX
Estimated exposure
masson the order of 100,000 to 1,000,000+ deployed AOS-CX switches worldwide, with the directly internet-exposed subset likely in the tens of thousands — HPE Aruba is a top enterprise campus switch vendor and ArubaOS-CX has been its flagship switch OS across the CX families for years, implying a six-to-seven-figure installed base; the provided data includes no scan counts or version…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

CVE-2026-73749: HPE ArubaOS-CX RCE

HPE patched CVE-2026-73749, a critical unauthenticated remote code execution flaw in ArubaOS-CX network switch software; affected devices need prompt updates.

HPE released patches for CVE-2026-73749, a critical unauthenticated remote code execution vulnerability in HPE Aruba Networking AOS-CX switch operating system. Published details are limited, but the flaw allows unauthenticated attackers to execute code on affected AOS-CX devices. Administrators running ArubaOS-CX should prioritize applying HPE's update.

SOCRadar · 11d agoVulnerabilityCVE-2026-73749