ZeroHour

CVE-2026-73770

large

Authenticated Arbitrary File Write in HPE ArubaOS-CX Allows Privileged Command Execution

CVSS 3.1
7.3 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-73770 is an authenticated arbitrary file write flaw (CWE-73, external control of file name or path) in HPE Aruba's AOS-CX network switch operating system. To exploit it, an attacker who already holds high-privileged credentials on the device, with adjacent network access, must write to a path they can influence, and the attack also depends on specific conditions and a required action by another user that the attacker cannot control — a high-complexity, multi-condition trigger. A successful attacker can create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying host operating system of the switch, beyond the switch's own CLI, with high impact to confidentiality, integrity, and availability. All organizations running affected AOS-CX releases are potentially affected, though practical exploitability is limited to environments where an authorized high-privilege account is compromised or abused. No public proof-of-concept, no listing in CISA KEV, and a low EPSS score (0.1%, ~4th percentile) indicate no known exploitation at this time.

What to do: Identify AOS-CX switches in your estate and check the HPE security advisory for this CVE to determine affected and fixed firmware versions, then upgrade to the recommended fixed release when available. In the interim, restrict management-plane access (CLI/API) to trusted administrators, audit accounts holding high-privileged credentials on these switches, and watch for signs of unexpected file changes or commands on the underlying OS. Given the low EPSS and absence of public PoC or KEV listing, standard patch-cycle prioritization is reasonable, with faster action for internet-reachable or high-value management networks.

Affected
HPE ArubaOS-CX
Estimated exposure
largeon the order of tens to hundreds of thousands of deployed AOS-CX switches in enterprise/campus networks (no public installed-base or internet-exposure counts… — AOS-CX is HPE Aruba's current enterprise campus switching OS deployed broadly across corporate, education, and healthcare networks, but with no public scan or active-install data the figure is an order-of-magnitude estimate from the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-73
Vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.