Executive brief
HPE Networking Fabric Composer is a web-based management interface for network fabric infrastructure. An unauthenticated attacker can exploit an open redirect vulnerability to trick users into visiting malicious websites, potentially compromising credentials or distributing malware without needing any authentication.
Technical details
The vulnerability is an open redirect flaw in the web-based management interface of HPE Networking Fabric Composer. An unauthenticated remote attacker can craft a URL with an arbitrary redirect target, causing users who access the legitimate interface to be redirected to an attacker-controlled website. The attack requires user interaction (clicking a malicious link) but no authentication. This could be leveraged in phishing campaigns to harvest credentials or deliver malware while appearing to originate from a trusted network management tool.
Affected products
- HPE Networking Fabric Composer
Timeline
- 2026-09-01: disclosed