Executive brief
A security vulnerability has been identified in the command line interface of HPE AOS-CX, the operating system used for modern enterprise network switches. An attacker with low-level access to the device's management interface could exploit this flaw to take full control of the switch. This could lead to unauthorized network changes, data interception, or a complete shutdown of network services.
Technical details
A buffer overflow vulnerability exists within the Command Line Interface (CLI) component of HPE AOS-CX. The flaw is reachable over the network and requires only low-privileged authentication to exploit. By sending specially crafted input to the CLI, an attacker can trigger a memory corruption condition to execute arbitrary code with elevated privileges on the underlying Linux-based operating system. Affected versions include various releases across the 10.13, 10.16, 10.17, and 10.18 branches; users are advised to update to patched versions as specified by the vendor.
Affected products
- HPE AOS-CX 10.13.0000 through 10.13.1170, 10.16.0000 through 10.16.1050, 10.17.0000 through 10.17.1020, 10.18.0000 before 10.18.0001
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory