Junglewise Threat Intelligence

CVE-2026-73752: HPE AOS-CX arbitrary file write in API endpoint

CVE-2026-73752 · Severity: high · CVSS 8.8 · Published 2026-09-01

Vendors: Hpe.

Executive brief

HPE AOS-CX is a network operating system used in Arista switches for cloud-scale networking. An unauthenticated attacker can exploit an API endpoint vulnerability to write arbitrary files to the system, potentially achieving remote code execution and full network device compromise.

Technical details

This vulnerability is an unauthenticated arbitrary file write flaw in an API endpoint of AOS-CX. The vulnerability requires network access to the API endpoint but no authentication credentials. Successful exploitation allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution (RCE). The attack vector is network-based and requires only that the API endpoint be reachable.

Affected products

  • HPE AOS-CX <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References