← Terug naar overzicht

Multiple vulnerabilities have been identified in a daemon component of HPE's AOS-CX network operating system. The flaws stem from improper processing of malformed input, allowing unauthenticated remote attackers to exploit them by sending specially crafted packets. Successful exploitation can result in remote code execution with elevated privileges. No authentication is required, making this particularly dangerous for exposed network devices. The vulnerabilities affect HPE AOS-CX, which runs on Aruba/HPE switching hardware. An official advisory has been published by HPE via their support portal. Organizations running AOS-CX should apply patches or mitigations as soon as they become available. The severity is high due to the unauthenticated RCE potential with privilege escalation.

Affected products

  • HPE AOS-CX

Related CVE's

  • CVE-2026-73749

Categories

  • Network Infrastructure
  • Zero-Day Vulnerabilities