Junglewise Threat Intelligence

CVE-2026-73768: HPE AOS-CX command line interface arbitrary command execution

CVE-2026-73768 · Severity: high · CVSS 7.3 · Published 2026-09-01

Vendors: Hpe.

Executive brief

HPE AOS-CX is a network operating system used in enterprise switches and routers. A vulnerability in its command-line interface fails to properly validate input, allowing an attacker with CLI access to execute arbitrary commands with root privileges, potentially compromising network infrastructure and enabling lateral movement within the data center.

Technical details

The vulnerability exists in the command-line interface (CLI) of AOS-CX and stems from improper input validation when processing malformed commands. An attacker with access to the CLI—either local or remote via SSH/Telnet—can craft malicious input that bypasses validation checks and results in arbitrary command execution with root privileges. No authentication bypass is required beyond initial CLI access. Successful exploitation grants complete system compromise on the affected switch or router. HPE has released patches; users should consult the HPE security bulletin for affected versions and available remediation.

Affected products

  • HPE AOS-CX <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References