ZeroHour

CVE-2026-73780

large

Missing CSRF Protection in HPE ArubaOS-CX Switch Web Management Interface

CVSS 3.1
8.3 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-73780 is a missing Cross-Site Request Forgery (CSRF) protection flaw (CWE-352) in the web-based management interface of HPE Aruba Networking AOS-CX switches. A remote, unauthenticated attacker who can convince an already-authenticated interface user to interact with a specially crafted URL can have that user's browser silently submit arbitrary input to the switch's management interface. Because these forged requests run with the victim's session, the attacker can execute arbitrary actions against the interface, with the potential for high-impact confidentiality, integrity, and availability consequences reflected in the 8.3 CVSS score. Any organization operating AOS-CX switches whose web management interface is used or reachable is affected, though the provided data does not specify affected version ranges. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known, and EPSS estimates only a 0.1% probability of exploitation within 30 days.

What to do: Upgrade AOS-CX switches to a fixed release identified in HPE's security advisory for CVE-2026-73780. Until patched, restrict the web-based management interface to trusted management networks or disable it where unused, and caution administrators not to open unsolicited links while logged in to the interface.

Affected
HPE ArubaOS-CX (AOS-CX) switch web-based management interface
Estimated exposure
largeroughly 10,000-100,000 AOS-CX switches with an in-use or reachable web management interface (installed base is larger, but exposure requires an authenticated… — HPE Aruba holds a major share of enterprise campus switching, implying an AOS-CX installed base in the hundreds of thousands, but this flaw additionally requires an authenticated web-UI user to click a crafted link, and switch management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.