Summary
CVE-2026-73749 is a critical, unauthenticated remote code execution vulnerability in HPE Aruba Networking’s AOS-CX switch operating system, caused by improper processing of malformed input in an AOS-CX daemon. The flaw is rated 9.8 (Critical) under CVSS v3.1, as it allows a remote attacker with no credentials to fully compromise an affected switch by sending specially crafted network packets.
Technical details
- Root cause: multiple buffer overflow issues in an AOS-CX daemon that improperly processes malformed input.
- Trigger: a remote attacker sends specially crafted packets to the affected daemon on the switch.
- Attack vector: network-based, no authentication or user interaction required, low attack complexity.
- Impact: successful exploitation can result in remote code execution with elevated privileges on the switch, fully compromising confidentiality, integrity, and availability.
- The vulnerability was identified through HPE’s internal security research process.
Affected software
- HPE Aruba Networking AOS-CX, versions:
- 10.18.0000 through 10.18.0001
- 10.17.0000 through 10.17.1021
- 10.16.0000 through 10.16.1051
- 10.13.0000 through 10.13.1180
- 10.10.0000 through 10.10.1180
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Consult HPE Security Bulletin HPESBNW05134 and update AOS-CX to a version outside the affected ranges listed above as soon as HPE publishes the corresponding fixed release for your platform.
- If a patch cannot be applied immediately:
- Restrict network access to switch management and control-plane services to trusted, dedicated management segments/VLANs only.
- Apply strict Layer 3+ access control policies so that only authorized hosts can reach the affected daemon.
- Disable or restrict any unnecessary exposed interfaces/services on the switch until the fix is applied.
- Monitor switch logs and network traffic for anomalous or malformed packets directed at management/control services.

