CVE-2026-73778
largePredictable default-password admin bypass in HPE ArubaOS-CX Credential Manager
CVE-2026-73778 is a weak-credential flaw (CWE-521) in the Credential Manager component of HPE ArubaOS-CX, in which devices ship with a predictable factory-default password. An unauthenticated remote attacker can exploit it by connecting to a switch that is in its factory-default state or has just completed Zero Touch Provisioning (ZTP) and has not yet had any administrator credentials configured. Successful exploitation grants the attacker full administrative control of the device during this initial setup window, allowing configuration changes and a foothold in the network. Only organizations deploying ArubaOS-CX switches that are left unconfigured (default or post-ZTP, no admin credentials set) are exposed; devices with credentials already assigned are not affected. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts near-term exploitation probability at 0.3%, so no active exploitation is known.
What to do: Upgrade affected ArubaOS-CX switches to the fixed release identified in HPE's security advisory, since no fixed version numbers are provided in this data. In the meantime, immediately configure administrator credentials on any new or ZTP-provisioned switches rather than leaving them at factory defaults, and audit the network for devices still sitting in a default/post-ZTP state. Restricting management-plane access to trusted networks also reduces exposure during the setup window.
| HPE ArubaOS-CX | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.
- Vendors
- hpe
- Products
- arubaos-cx
- Weakness
- CWE-521
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.