Executive brief
AOS-CX is a network operating system used in HPE switches and routers to manage enterprise network infrastructure. A command injection vulnerability in the API endpoint allows authenticated administrators to execute arbitrary commands with elevated privileges on the underlying system, potentially compromising network availability and enabling lateral movement within the infrastructure.
Technical details
The vulnerability is a command injection flaw in the API endpoint of AOS-CX that fails to properly sanitize user-supplied input before executing system commands. An authenticated remote attacker with administrative privileges can inject arbitrary shell commands through the API, resulting in arbitrary code execution as a privileged user on the underlying operating system. The attack requires valid administrative credentials and network access to the API endpoint; no user interaction is needed. Successful exploitation could allow an attacker to gain full control of the affected device and potentially pivot to other network components.
Affected products
- HPE AOS-CX <UNKNOWN>
Timeline
- 2026-09-01: disclosed