CVE-2026-73753
8.8Hewlett Packard Enterprise · AOS-CX
A vulnerability in HPE AOS-CX command-line operations allows authenticated low-privileged users to execute arbitrary commands with elevated system privileges.
Executive summary
A high-severity command injection vulnerability in HPE AOS-CX allows low-privileged users to escalate their privileges to the underlying operating system.
Vulnerability
This flaw involves improper input validation within command-line operations, enabling an authenticated low-privileged user to achieve arbitrary command execution as a privileged user.
Business impact
Successful exploitation grants an attacker full administrative control over the affected networking hardware. Given the CVSS score of 8.8, this vulnerability poses a significant risk to network integrity, potentially allowing unauthorized access to sensitive traffic, configuration tampering, or complete denial of service within the network infrastructure.
Remediation
Immediate Action: Review the official HPE security advisory and apply the necessary firmware updates as soon as they become available for your specific hardware model.
Proactive Monitoring: Monitor system logs for unauthorized command execution attempts or unusual changes to administrative user activity on the AOS-CX console.
Compensating Controls: Restrict administrative access to the command-line interface to only trusted personnel and implement strict network access control lists to limit the exposure of management interfaces.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical risk to the security of the network fabric due to the potential for privilege escalation. Administrators should prioritize identifying affected AOS-CX instances and prepare for an immediate deployment of vendor-supplied patches to mitigate the threat of arbitrary command execution.
More Hewlett Packard Enterprise CVEs
Sources
Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.