CVE-2026-73750
8.8Hewlett Packard Enterprise · AOS-CX
The authentication module in HPE AOS-CX incorrectly processes malformed input, allowing an authenticated remote attacker to potentially achieve remote code execution or cause a denial of service.
Executive summary
A vulnerability in the HPE AOS-CX authentication module allows an authenticated remote attacker to execute arbitrary code or disrupt network services.
Vulnerability
This flaw exists in the authentication module, where improper processing of malformed or truncated input can be leveraged by an authenticated remote attacker via a compromised or hostile authentication server.
Business impact
Successful exploitation of this vulnerability poses a severe risk to network infrastructure, as it could grant an attacker the ability to execute code with elevated privileges on the network switch. Given the CVSS score of 8.8, this represents a high-severity threat that could lead to full system compromise, unauthorized network traffic interception, or prolonged denial of service across critical segments.
Remediation
Immediate Action: Review the vendor advisory at the provided HPE support link to identify available firmware updates for the specific AOS-CX version in use and apply them immediately.
Proactive Monitoring: Monitor authentication logs and RADIUS or TACACS+ server traffic for anomalous patterns or unexpected input strings originating from the authentication source.
Compensating Controls: Restrict management access to the switch authentication interface to known, trusted management VLANs or IP addresses to limit the exposure of the vulnerable module.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for remote code execution, this vulnerability should be prioritized for remediation within your next maintenance window. Administrators must ensure that authentication servers are secured and that the latest firmware patches from HPE are deployed to eliminate the flaw in the authentication module.
More Hewlett Packard Enterprise CVEs
Sources
Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.