Multiple security vulnerabilities affecting AOS-CX switch software versions The flaws affect several AOS-CX branches have been identified in HPE AOS-CX switch software, affecting several branches including 10.18.0001 and below, 10.17.1021 and below, 10.16.1051 and below, 10.13.1180 and below, and 10.10.1180 and below. The most severe vulnerability.
CVE-2026-73749 (CVSS 9.8 — Severity): A buffer overflow bug in an AOS-CX daemon allows an attacker to send specially crafted packets and execute code with elevated privileges on the device.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting AOS-CX switch software versions The flaws affect several AOS-CX branches have been identified in HPE AOS-CX switch software, affecting several branches including 10.18.0001 and below, 10.17.1021 and below, 10.16.1051 and below, 10.13.1180 and below, and 10.10.1180 and below. The most severe vulnerability.
CVE-2026-73749 (CVSS 9.8 — Severity): A buffer overflow bug in an AOS-CX daemon allows an attacker to send specially crafted packets and execute code with elevated privileges on the device.[emaillocker id="1283"]
CVE-2026-73752 (CVSS 8.8 — Severity): An unauthenticated arbitrary file write vulnerability can lead to remote code execution.
CVE-2026-73782 (CVSS 8.8 — Severity): An unauthenticated format string bug leads to remote code execution.
CVE-2026-73751: Authenticated Remote Command Injection in Web-based Management Interface allows an attacker to inject commands with elevated privileges.
CVE-2026-73750 (CVSS 8.8 — Severity): A buffer overflow bug in an AOS-CX daemon allows an attacker to execute code with elevated privileges on the device.
CVE-2026-73778 (CVSS 8.1 — Severity): An attacker can abuse a predictable factory-default password during initial setup.
These vulnerabilities collectively present significant remote execution risks for networks relying on HPE Aruba Networking enterprise switches.
We recommend you to update AOS-CX to version 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181.
The following reports contain further technical details:
[/emaillocker]