ZeroHour

CVE-2026-73778

large

Predictable default-password admin bypass in HPE ArubaOS-CX Credential Manager

CVSS 3.1
9.8 critical
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-73778 is a weak-credential flaw (CWE-521) in the Credential Manager component of HPE ArubaOS-CX, in which devices ship with a predictable factory-default password. An unauthenticated remote attacker can exploit it by connecting to a switch that is in its factory-default state or has just completed Zero Touch Provisioning (ZTP) and has not yet had any administrator credentials configured. Successful exploitation grants the attacker full administrative control of the device during this initial setup window, allowing configuration changes and a foothold in the network. Only organizations deploying ArubaOS-CX switches that are left unconfigured (default or post-ZTP, no admin credentials set) are exposed; devices with credentials already assigned are not affected. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts near-term exploitation probability at 0.3%, so no active exploitation is known.

What to do: Upgrade affected ArubaOS-CX switches to the fixed release identified in HPE's security advisory, since no fixed version numbers are provided in this data. In the meantime, immediately configure administrator credentials on any new or ZTP-provisioned switches rather than leaving them at factory defaults, and audit the network for devices still sitting in a default/post-ZTP state. Restricting management-plane access to trusted networks also reduces exposure during the setup window.

Affected
HPE ArubaOS-CX
Estimated exposure
largetens of thousands of switches in factory-default/post-ZTP state (subset of ArubaOS-CX's large enterprise campus installed base) — ArubaOS-CX is HPE's widely deployed campus switch operating system with an installed base plausibly in the hundreds of thousands of devices, but only units left in factory-default or post-ZTP state without configured admin credentials are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-521
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.