CVE-2026-73752
largeUnauthenticated Arbitrary File Write in HPE Aruba AOS-CX Switch API
ArubaOS-CX, the operating system running on HPE Aruba's CX-series campus switches, contains an unauthenticated arbitrary file-write vulnerability (path traversal, CWE-22) in one of its API endpoints. An attacker who can reach the vulnerable endpoint - the CVSS vector indicates adjacent-network access, such as a device on a connected LAN or management segment - can send crafted requests that write files to arbitrary locations on the switch's underlying operating system. By overwriting or creating system files, the attacker can potentially achieve remote code execution on the device, with high impact on confidentiality, integrity, and availability. Any organization running AOS-CX switches is potentially affected; the available data does not specify which firmware version ranges are vulnerable. As of now there is no public proof-of-concept, no known in-the-wild exploitation, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.3% probability of exploitation in the next 30 days.
What to do: Check the HPE Aruba security advisory (CNA: [email protected]) for the list of affected AOS-CX firmware versions and upgrade to the fixed release; no fixed versions are stated in the available data. Until patching, restrict access to switch management and API interfaces to trusted management VLANs or jump hosts, since exploitation requires adjacent network access and no authentication. Given the absence of a public PoC, KEV listing, and low EPSS score, this warrants prompt but not emergency remediation.
| HPE ArubaOS-CX (AOS-CX) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.