CVE-2026-73781

8.4

Hewlett Packard Enterprise · AOS-CX

A stored cross-site scripting (XSS) vulnerability in the HPE AOS-CX web management interface allows an authenticated attacker to execute arbitrary scripts in an administrator's browser.

Executive summary

An authenticated remote attacker can exploit a stored XSS vulnerability in the HPE AOS-CX web management interface to compromise administrative sessions and execute arbitrary code in a victim's browser.

Vulnerability

This is a stored cross-site scripting (XSS) flaw located within the web-based management interface. The vulnerability requires an authenticated attacker with high privileges to inject malicious scripts that execute within the context of an administrative user's session.

Business impact

Successful exploitation poses a significant risk to network infrastructure integrity, as an attacker could hijack administrative sessions, modify configurations, or perform unauthorized actions on the network switch. Given the CVSS score of 8.4, this vulnerability is classified as High severity, reflecting the potential for complete compromise of the management interface and subsequent impact on network operations.

Remediation

Immediate Action: Review the official HPE security advisory and apply the recommended firmware updates as soon as they become available for your specific model and version.

Proactive Monitoring: Implement strict access control lists for the management interface and monitor administrative logs for suspicious script injections or unusual activity following user logins.

Compensating Controls: Restrict access to the web management interface to trusted management subnets only and utilize a Web Application Firewall where feasible to inspect and block malicious web requests.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing HPE AOS-CX switches should prioritize the identification of affected units within their environment. Because this vulnerability targets the administrative interface, administrators should exercise extreme caution when accessing the web console until patches are applied to mitigate the risk of session hijacking and unauthorized command execution.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.