Executive brief
The web-based management interface for Hewlett Packard Enterprise AOS-CX network switches lacks proper Cross-Site Request Forgery (CSRF) protection. An attacker can trick an authenticated administrator into visiting a malicious website, which could then execute unauthorized administrative commands on the affected switch, potentially disrupting network operations or modifying configurations.
Technical details
The web-based management interface of AOS-CX switches fails to implement proper CSRF token validation on certain endpoints. The vulnerability allows an unauthenticated attacker to craft a malicious URL that, when visited by an authenticated administrator, executes arbitrary administrative actions against the switch without the user's knowledge or consent. This requires user interaction (clicking a malicious link) and the target must have an active authenticated session. An attacker could modify switch configurations, create backdoor accounts, or disrupt network operations. Hewlett Packard Enterprise has published a security advisory with patches available.
Affected products
- Hewlett Packard Enterprise AOS-CX <UNKNOWN>
Timeline
- 2026-09-01: disclosed