Junglewise Threat Intelligence

CVE-2026-73782: Hewlett Packard Enterprise AOS-CX format string vulnerability in CLI

CVE-2026-73782 · Severity: high · CVSS 8.8 · Published 2026-09-01

Vendors: Hewlett Packard Enterprise.

Executive brief

AOS-CX is a network operating system used in HPE switches and routers to manage network traffic and connectivity. A format string vulnerability in the command-line interface allows unauthenticated attackers to execute arbitrary code with elevated privileges, potentially compromising the entire network infrastructure and enabling lateral movement to connected systems.

Technical details

A format string vulnerability exists in the command-line interface (CLI) parsing component of AOS-CX that fails to properly validate user-supplied input. The vulnerability is exploitable over the network without authentication, allowing an attacker to craft malicious input containing format string specifiers that can read from or write to arbitrary memory locations. Successful exploitation enables arbitrary code execution with privileged access to the underlying operating system, potentially resulting in complete system compromise.

Affected products

  • Hewlett Packard Enterprise AOS-CX

Timeline

  • 2026-09-01: disclosed

References