CVE-2026-73780

8.3

Hewlett Packard Enterprise · AOS-CX

A Cross-Site Request Forgery (CSRF) vulnerability in the AOS-CX web management interface allows remote attackers to execute unauthorized actions via a victim's authenticated session.

Executive summary

A high-severity Cross-Site Request Forgery vulnerability in the AOS-CX web interface permits remote attackers to execute arbitrary actions by deceiving an authenticated administrative user.

Vulnerability

This is a Cross-Site Request Forgery (CWE-352) vulnerability residing in the web-based management interface. While the attacker is technically unauthenticated, the exploit requires interaction from an already authenticated user to trigger malicious inputs.

Business impact

The vulnerability carries a CVSS score of 8.3, reflecting the potential for complete compromise of confidentiality, integrity, and availability within the management interface. Successful exploitation could allow an attacker to modify network configurations, alter administrative settings, or disrupt critical connectivity, leading to significant operational downtime and potential security breaches within the network infrastructure.

Remediation

Immediate Action: Consult the vendor advisory at the provided HPE support link to identify the specific firmware release that addresses this CSRF flaw and apply the update immediately.

Proactive Monitoring: Review web management access logs for suspicious or unusual URL requests that originate from unexpected sources or occur outside of established maintenance windows.

Compensating Controls: Implement strict network access control lists (ACLs) to restrict access to the web management interface to trusted administrative IP addresses only, effectively reducing the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high impact of a compromised network switch, administrators must prioritize the application of vendor-supplied firmware updates. Until patches are applied, ensure that administrative users log out of the switch management interface immediately after completing tasks to minimize the window of opportunity for an attacker to hijack an active session.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.