Executive brief
HPE AOS-CX is a network operating system used in enterprise switching infrastructure. Authenticated attackers with API access can exploit path traversal vulnerabilities to write arbitrary files to the underlying system, potentially achieving remote code execution and compromising network device availability and integrity.
Technical details
The vulnerability is an authenticated path traversal flaw in AOS-CX API endpoints that allows attackers to bypass directory restrictions and write arbitrary files to the operating system. The attack requires valid API credentials but does not require additional user interaction. Successful exploitation can lead to arbitrary file write and remote code execution on the affected network device. HPE has released patches to address this issue; users should update to patched versions immediately.
Affected products
- HPE AOS-CX
Timeline
- 2026-09-01: disclosed