DEV Community

Cover image for HPE Patches Critical Remote Code Execution Flaw in ArubaOS-CX Switches
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

HPE Patches Critical Remote Code Execution Flaw in ArubaOS-CX Switches

Summary

HPE patched 34 vulnerabilities in ArubaOS-CX, including a critical buffer overflow (CVE-2026-73749) that allows unauthenticated remote code execution. The update also addresses multiple high-severity flaws enabling command injection, authentication bypass, and unauthorized file writes.

Take Action:

If you run HPE Aruba CX switches (10000, 6400, 8325, 6000 series), first make sure their management interfaces are not reachable from the internet and only accessible from a dedicated management VLAN on trusted networks. Then update the switches to AOS-CX 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, or 10.10.1181, and change any factory-set passwords while you're there.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)