Junglewise Threat Intelligence

CVE-2026-73757: HP AOS-CX server-side request forgery in web management

CVE-2026-73757 · Severity: medium · CVSS 6.4 · Published 2026-09-01

Vendors: Hp.

Executive brief

AOS-CX is HP's operating system for network switches and infrastructure devices, managed through a web-based interface. An authenticated attacker could exploit an SSRF vulnerability to probe the internal network, enumerate sensitive information about the device, and potentially modify configuration settings. This could compromise network security and expose internal infrastructure details.

Technical details

The vulnerability is a server-side request forgery (SSRF) flaw in the web-based management interface of AOS-CX. An authenticated remote attacker can exploit this to make the AOS-CX host initiate arbitrary internal requests, allowing enumeration of internal network structure and disclosure of sensitive information. Attack requires authentication to the management interface. A successful exploit enables limited information disclosure and potential modification of sensitive data, but does not grant unauthenticated access. Patches are available from HP.

Affected products

  • HP AOS-CX <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References