Junglewise Threat Intelligence

CVE-2026-63454: HPE AOS-CX path traversal in CLI

CVE-2026-63454 · Severity: high · CVSS 7.2 · Published 2026-07-21

Vendors: Hpe.

Executive brief

HPE AOS-CX is the operating system used in modern enterprise network switches. A security flaw allows an authorized user with high-level permissions to bypass file restrictions and copy sensitive system files to accessible locations. This could allow an attacker to gain full control over the switch, potentially leading to network disruptions or unauthorized access to data passing through the device.

Technical details

An authenticated path traversal vulnerability exists in the AOS-CX network operating system. The flaw resides in the command line interface (CLI) of the underlying operating system, where insufficient input validation allows an attacker to traverse directories. An attacker with high privileges (PR:H) can exploit this over the network to copy arbitrary system files into user-readable locations. This capability can be further leveraged to achieve remote code execution (RCE) on the affected switch. The vulnerability impacts multiple versions including the 10.13, 10.16, 10.17, and 10.18 branches.

Affected products

  • HPE AOS-CX 10.13.0000 through 10.13.1180, 10.16.0000 through 10.16.1050, 10.17.0000 through 10.17.1020, 10.18.0000 before 10.18.0001

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References