Executive brief
A security flaw exists in the web management interface of AOS-CX network switches. An attacker can trick a legitimate user into clicking a malicious link that redirects them from the official switch management page to a fraudulent website. This can be used in phishing campaigns to steal administrative credentials or deliver malware to IT staff.
Technical details
The vulnerability is classified as an Open Redirect (CWE-601) within the web-based management interface of HPE Aruba AOS-CX switches. It stems from insufficient validation of user-supplied input used in redirection targets. An unauthenticated remote attacker can exploit this by crafting a malicious URL and persuading a user to click it. While the vulnerability does not allow direct access to switch data, it is a primary vector for phishing attacks and credential harvesting. Patches have been released for various branches including 10.10.1180, 10.13.1161, 10.16.1030, and 10.17.1001.
Affected products
- HPE Aruba Networking AOS-CX 10.06.0000 to 10.10.1180, 10.13.0000 to 10.13.1161, 10.16.0000 to 10.16.1030, 10.17.0000 to 10.17.1001
Timeline
- 2026-03-11: disclosed: Initial disclosure by HPE
- 2026-03-11: advisory: NVD publication date