ZeroHour

CVE-2026-73782

large

Format String Flaw in HPE ArubaOS-CX CLI Enables Unauthenticated RCE

CVSS 3.1
8.8 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-73782 is a format string vulnerability (CWE-134) in the command line interface of HPE Aruba's AOS-CX network switch operating system. An unauthenticated attacker who can reach the switch CLI from an adjacent network can supply crafted format string input that triggers the flaw, and successful exploitation results in arbitrary code execution as a privileged user on the switch's underlying operating system. This effectively gives the attacker root-level control of the device, enabling configuration changes, traffic interception or manipulation, and potential persistence inside the enterprise network. Any organization running AOS-CX switches is potentially affected, although the specific affected and fixed firmware versions are not stated in the available data. Exploitation is not confirmed in the wild: the flaw is not in CISA's KEV catalog, has no known public proof-of-concept, and carries a low EPSS probability of 0.3%.

What to do: Monitor the HPE security advisory (CNA: [email protected]) for the list of affected AOS-CX versions and upgrade to the fixed firmware release when published. In the meantime, restrict CLI reachability by limiting SSH/telnet management access to trusted management VLANs via ACLs and removing any exposure from user-facing networks, since the attack vector is adjacent. With no public PoC or KEV listing, treating this as standard-cycle patching rather than emergency response is defensible.

Affected
HPE ArubaOS-CX (AOS-CX)
Estimated exposure
large≈ hundreds of thousands of deployed AOS-CX switches worldwide (estimate); the subset with CLI reachable from an adjacent attacker network is likely smaller — AOS-CX is HPE Aruba's flagship OS across its enterprise campus and data center switch lines and has shipped broadly since 2017, implying an installed base on the order of hundreds of thousands of units, but the vulnerable version set and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

Vendors
hpe
Products
arubaos-cx
Weakness
CWE-134
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.