Executive brief
AOS-CX is a network operating system used in enterprise switches and routers. An authenticated path traversal flaw in its web-based management interface allows an attacker with valid credentials to read sensitive files from the underlying system, potentially exposing configuration data, credentials, and other confidential information that could enable further compromise.
Technical details
This is a path traversal vulnerability affecting the web-based management interface of AOS-CX. The vulnerability requires prior authentication, limiting the attack surface to users or systems with valid management credentials. An attacker can exploit the flaw to escape directory restrictions and access arbitrary files on the operating system using directory traversal sequences (e.g., "../" or "..\"). Successful exploitation enables unauthorized read access to sensitive files including system configuration, credentials, and application data. Patches are expected from HPE; users should consult the HPE security advisory for patched versions and interim mitigations.
Affected products
- HPE AOS-CX
Timeline
- 2026-09-01: disclosed