CVE-2026-73782

8.8

Hewlett Packard Enterprise · AOS-CX

A format string vulnerability in the AOS-CX command line interface allows unauthenticated attackers to achieve remote code execution as a privileged user.

Executive summary

A critical format string vulnerability in Hewlett Packard Enterprise AOS-CX allows unauthenticated remote code execution, posing a severe risk to network infrastructure integrity.

Vulnerability

This is a format string vulnerability residing in the command line interface of the AOS-CX operating system. An unauthenticated attacker can leverage this flaw to execute arbitrary code with elevated privileges on the underlying system.

Business impact

Successful exploitation grants an attacker full control over the affected network device, potentially leading to unauthorized network traffic interception, lateral movement, or complete denial of service. While the CVSS score of 8.8 indicates a high severity, the ability to execute code as a privileged user on network infrastructure represents a significant threat to organizational security and operational continuity.

Remediation

Immediate Action: Review the official Hewlett Packard Enterprise security advisory at the linked support portal to identify available firmware updates for your specific device model.

Proactive Monitoring: Monitor network device logs for unusual command line activity or unexpected system reboots that may indicate exploitation attempts.

Compensating Controls: Restrict access to the command line interface to trusted management networks only and utilize strong access control lists to limit exposure.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS severity and the potential for full system compromise, administrators should prioritize this vulnerability for immediate remediation. Apply vendor-provided patches as soon as they become available to ensure the continued security and integrity of your network environment.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by internal security research at HPE Networking., per the CVE Program record.