ZeroHour

CVE-2026-73765

mass

Authenticated Path Traversal in HPE ArubaOS-CX Switch API Enables RCE

CVSS 3.1
7.2 high
EPSS
<1%p49
Published
()
Modified
AI analysis

HPE has disclosed CVE-2026-73765, an authenticated path traversal flaw (CWE-22) in the API endpoints of ArubaOS-CX, the network operating system that runs on HPE Aruba Networking CX-series switches. An attacker with high-privilege (administrator-level) credentials sends a crafted request to an affected API endpoint, and unsanitized path handling lets file writes escape their intended directory on the underlying operating system. Because arbitrary file write is possible, the flaw can be leveraged to achieve remote code execution on the switch; the CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:U) reflects that network access and privileged authentication are required, but no user interaction. Any organization running ArubaOS-CX switches, typically in enterprise campus, branch, or data-center networks, is potentially affected, though the available data does not specify which firmware versions or which API endpoints are impacted. There is no evidence of exploitation so far: the flaw is not in CISA KEV, EPSS assigns a 0.7% probability of exploitation within 30 days (around the median), and no public proof-of-concept is known.

What to do: Upgrade ArubaOS-CX switches to the fixed firmware release identified in HPE's security advisory (specific versions are not listed in this data), which is the primary remediation since exploitation requires only admin-level credentials. In the interim, restrict access to the switch REST/API endpoints and management interface to trusted management networks and audit which accounts hold administrator privileges, since high-privilege authentication is a prerequisite. Monitor the HPE Aruba security alerts portal for the advisory text and updated firmware releases.

Affected
HPE ArubaOS-CX
Estimated exposure
masshigh hundreds of thousands to a few million deployed ArubaOS-CX switch units worldwide (mostly reachable only via internal management networks, not the public… — HPE Aruba is one of the largest enterprise-switch vendors and ArubaOS-CX has shipped broadly across campus and data-center deployments since its 2017 introduction, so the global installed base plausibly exceeds 100,000 systems, although…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authenticated path traversal vulnerabilities exist in API endpoints of AOS-CX. Successful exploitation of these vulnerabilities allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.