CVE-2026-73752

8.8

Hewlett Packard Enterprise · AOS-CX

An unauthenticated arbitrary file write vulnerability in an AOS-CX API endpoint allows attackers to write files to the operating system, potentially leading to remote code execution.

Executive summary

A critical arbitrary file write vulnerability in Hewlett Packard Enterprise AOS-CX poses a severe risk of unauthorized system access and remote code execution.

Vulnerability

This is an unauthenticated arbitrary file write vulnerability affecting an API endpoint within AOS-CX. The flaw permits an attacker without valid credentials to write arbitrary files to the underlying operating system, which can be leveraged to achieve remote code execution.

Business impact

The ability to write arbitrary files to the operating system provides an attacker with significant control over the network device. Given the CVSS score of 8.8, this vulnerability represents a high risk that could lead to complete system compromise, unauthorized data access, and persistent lateral movement within the network infrastructure.

Remediation

Immediate Action: Review the official Hewlett Packard Enterprise security advisory at the provided reference link to identify available firmware updates or specific configuration changes to disable the vulnerable API endpoint.

Proactive Monitoring: Monitor network device logs for unusual API traffic, specifically looking for POST or PUT requests to undocumented or sensitive API paths, as well as unexpected system file modifications.

Compensating Controls: Restrict access to the management interface of the AOS-CX devices to authorized management subnets only, and employ a Web Application Firewall or similar inspection tool to block malicious API payloads targeting the affected endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention from network administrators. Because the flaw allows for unauthenticated remote code execution, it is imperative to restrict management access to the affected devices and apply the vendor-provided firmware updates as soon as they become available to eliminate the underlying security risk.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.