CVE-2026-73751
8.8Hewlett Packard Enterprise · AOS-CX
A command injection vulnerability in the HPE AOS-CX web-based management interface allows low-privileged authenticated users to execute arbitrary commands on the underlying operating system.
Executive summary
An authenticated command injection vulnerability in HPE AOS-CX allows low-privileged users to achieve remote code execution, posing a significant risk to network infrastructure security.
Vulnerability
This is a command injection flaw within the web-based management interface. It requires a low-privileged authenticated user to submit crafted input that the application fails to sanitize before execution.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its high severity and potential for full system compromise. Successful exploitation grants an attacker the ability to run arbitrary commands with the privileges of the management service, potentially leading to unauthorized network access, data exfiltration, or complete disruption of network services.
Remediation
Immediate Action: Review the official HPE security advisory and apply the recommended firmware updates as soon as they become available for your specific hardware platform.
Proactive Monitoring: Monitor management interface access logs for suspicious input patterns, including unexpected characters or command strings, and alert on unauthorized attempts to access sensitive system management endpoints.
Compensating Controls: Restrict access to the web-based management interface to authorized administrative segments only, utilizing network access control lists or a VPN to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the critical nature of network switch management, this vulnerability requires immediate attention. Security teams should prioritize patching affected AOS-CX devices and verify that management interfaces are not exposed to untrusted network zones.
More Hewlett Packard Enterprise CVEs
Sources
Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.