Junglewise Threat Intelligence

CVE-2026-73780: Hewlett Packard Enterprise AOS-CX CSRF in web management interface

CVE-2026-73780 · Severity: high · CVSS 8.3 · Published 2026-09-01

Vendors: Hewlett Packard Enterprise.

Executive brief

The web-based management interface for Hewlett Packard Enterprise AOS-CX network switches lacks proper Cross-Site Request Forgery (CSRF) protection. An attacker can trick an authenticated administrator into visiting a malicious website, which could then execute unauthorized administrative commands on the affected switch, potentially disrupting network operations or modifying configurations.

Technical details

The web-based management interface of AOS-CX switches fails to implement proper CSRF token validation on certain endpoints. The vulnerability allows an unauthenticated attacker to craft a malicious URL that, when visited by an authenticated administrator, executes arbitrary administrative actions against the switch without the user's knowledge or consent. This requires user interaction (clicking a malicious link) and the target must have an active authenticated session. An attacker could modify switch configurations, create backdoor accounts, or disrupt network operations. Hewlett Packard Enterprise has published a security advisory with patches available.

Affected products

  • Hewlett Packard Enterprise AOS-CX <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References