CVE-2026-73767
largeAuthenticated command injection in HPE ArubaOS-CX switch CLI
CVE-2026-73767 is an authenticated command injection flaw (CWE-78) in the command line interface of HPE Aruba's AOS-CX network switch operating system. It is triggered by an attacker who already holds high-privilege (admin-level) credentials and submits crafted input to CLI commands over the network. Successful exploitation yields execution of arbitrary commands as a privileged user on the switch's underlying operating system, effectively giving full control of the device (high impact to confidentiality, integrity and availability). Any organization operating AOS-CX switches is potentially affected, though the high privilege requirement limits exposure to users with administrative CLI access. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 1% probability of exploitation within 30 days.
What to do: Apply the AOS-CX firmware update designated in HPE's security advisory for this CVE, since no fixed version numbers are given in the available data. Until patching, restrict switch management/CLI access to trusted administrative networks and audit for unexpected local or remote accounts with admin rights. No workarounds or exploitation activity are documented, so priority is moderate, but devices with broadly shared admin credentials should be patched first.
| HPE ArubaOS-CX (AOS-CX switch operating system) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Authenticated command injection vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.