Summary
CVE-2026-73778 is a vulnerability in the Credential Manager component of HPE Aruba Networking AOS-CX that allows unauthorized administrative access through a predictable factory-default password. The issue only affects switches that are still in a factory-default or post-Zero Touch Provisioning (ZTP) state, before an administrator has configured device credentials. HPE has rated this vulnerability HIGH severity with a CVSS v3.1 base score of 8.1.
Technical details
- Root cause: The Credential Manager component ships with a predictable, factory-default administrator password.
- Trigger conditions: The device must be in its factory-default or post-ZTP state, i.e., before an administrator has set custom credentials.
- Attack vector: Network-based; the CVSS vector indicates high attack complexity, no privileges required, and no user interaction.
- Impact: Successful exploitation gives an unauthenticated remote attacker full administrative control of the affected switch during the initial setup process, with high impact to confidentiality, integrity, and availability.
Affected software
- HPE Aruba Networking AOS-CX 10.18.0000 through 10.18.0001
- HPE Aruba Networking AOS-CX 10.17.0000 through 10.17.1021
- HPE Aruba Networking AOS-CX 10.16.0000 through 10.16.1051
- HPE Aruba Networking AOS-CX 10.13.0000 through 10.13.1180
- HPE Aruba Networking AOS-CX 10.10.0000 through 10.10.1180
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Consult and apply the fixed AOS-CX release identified in HPE Security Bulletin HPESBNW05134 for your specific switch series/version train, as the bulletin is the authoritative source for patched build numbers.
- Before patching / as a workaround: Complete initial administrator credential configuration (change the default password) immediately upon first boot or after ZTP, before connecting the device’s management interfaces to any untrusted or internet-reachable network. Restrict network access to management interfaces to trusted hosts/VLANs until credentials have been set and the device is patched.

