ZeroHour

CVE-2026-73752

large

Unauthenticated Arbitrary File Write in HPE Aruba AOS-CX Switch API

CVSS 3.1
8.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

ArubaOS-CX, the operating system running on HPE Aruba's CX-series campus switches, contains an unauthenticated arbitrary file-write vulnerability (path traversal, CWE-22) in one of its API endpoints. An attacker who can reach the vulnerable endpoint - the CVSS vector indicates adjacent-network access, such as a device on a connected LAN or management segment - can send crafted requests that write files to arbitrary locations on the switch's underlying operating system. By overwriting or creating system files, the attacker can potentially achieve remote code execution on the device, with high impact on confidentiality, integrity, and availability. Any organization running AOS-CX switches is potentially affected; the available data does not specify which firmware version ranges are vulnerable. As of now there is no public proof-of-concept, no known in-the-wild exploitation, the flaw is not in CISA's KEV catalog, and EPSS assigns it a low 0.3% probability of exploitation in the next 30 days.

What to do: Check the HPE Aruba security advisory (CNA: [email protected]) for the list of affected AOS-CX firmware versions and upgrade to the fixed release; no fixed versions are stated in the available data. Until patching, restrict access to switch management and API interfaces to trusted management VLANs or jump hosts, since exploitation requires adjacent network access and no authentication. Given the absence of a public PoC, KEV listing, and low EPSS score, this warrants prompt but not emergency remediation.

Affected
HPE ArubaOS-CX (AOS-CX)
Estimated exposure
large~100,000+ deployed AOS-CX switch instances worldwide (installed base of HPE's flagship campus switching OS); internet-exposed management interfaces likely far… — ArubaOS-CX is the operating system of a top-tier enterprise campus switching vendor with a broad global installed base, but the CVSS adjacency requirement means most switch management APIs sit on internal/management networks rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-22
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.