ZeroHour

CVE-2026-73767

large

Authenticated command injection in HPE ArubaOS-CX switch CLI

CVSS 3.1
7.2 high
EPSS
1%p61
Published
()
Modified
AI analysis

CVE-2026-73767 is an authenticated command injection flaw (CWE-78) in the command line interface of HPE Aruba's AOS-CX network switch operating system. It is triggered by an attacker who already holds high-privilege (admin-level) credentials and submits crafted input to CLI commands over the network. Successful exploitation yields execution of arbitrary commands as a privileged user on the switch's underlying operating system, effectively giving full control of the device (high impact to confidentiality, integrity and availability). Any organization operating AOS-CX switches is potentially affected, though the high privilege requirement limits exposure to users with administrative CLI access. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 1% probability of exploitation within 30 days.

What to do: Apply the AOS-CX firmware update designated in HPE's security advisory for this CVE, since no fixed version numbers are given in the available data. Until patching, restrict switch management/CLI access to trusted administrative networks and audit for unexpected local or remote accounts with admin rights. No workarounds or exploitation activity are documented, so priority is moderate, but devices with broadly shared admin credentials should be patched first.

Affected
HPE ArubaOS-CX (AOS-CX switch operating system)
Estimated exposure
largehundreds of thousands of AOS-CX switches deployed worldwide, with only administrative CLI users directly exposed (unknown precise count) — HPE Aruba is a top-tier enterprise campus switching vendor, so its installed base of AOS-CX switches plausibly numbers in the hundreds of thousands, but these devices normally sit on internal networks and require admin-level login, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.