CVE-2026-73782CWE-134

CVE-2026-73782

High · published September 2, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
18.8
In the wild
Unconfirmed
What it is

A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00269 · 18.8th percentile
Weakness
CWE-134 · Use of Externally-Controlled Format String
Published
2026-09-02T01:18Z
Affected products (5)
ProductVersionsFixed in
hpe/arubaos-cx≤ 10.10.1180
hpe/arubaos-cx≥ 10.13.0000, ≤ 10.13.1180
hpe/arubaos-cx≥ 10.16.0000, ≤ 10.16.1051
hpe/arubaos-cx≥ 10.17.0000, ≤ 10.17.1021
hpe/arubaos-cxall versions
References (1)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 20:28Z
    Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX
    cvelistv5