Sceawere

Vulnerability Detail

CVE-2026-73766UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AOS-CX API Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
4h ago
Vendor
Hewlett Packard Enterprise (HPE)
Product
AOS-CX
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Command injection vulnerabilities in the API endpoint of AOS-CX could allow an authenticated remote attacker with administrative privileges to inject arbitrary commands. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-01T21:18:43.397Z",
  "pubdate": "2026-09-01T21:18:43.397Z",
  "executiveSummary": "A command injection vulnerability exists within the API endpoint of AOS-CX, enabling authenticated remote attackers with administrative privileges to execute arbitrary system-level commands.\nThis vulnerability is classified as an OS Command Injection flaw, which allows unauthorized code execution within the underlying operating system of the network device.\nThe scope of impact is critical, as successful exploitation grants the attacker privileged access to the appliance's host OS, potentially leading to full system compromise, data exfiltration, or lateral movement within the network infrastructure.\nExploitation requires the attacker to possess pre-existing administrative-level credentials to interact with the vulnerable API surface, effectively elevating their already privileged status to full operating system control.\nThe risk implication is significant for organizations relying on AOS-CX for secure network management, as this vulnerability bypasses the intended boundary between the network operating system's API abstraction layer and the underlying host environment.\nThere are no requirements for physical access to the device, as the attack is orchestrated remotely through the network interface.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper sanitization of user-supplied input provided to the AOS-CX API endpoint. The application fails to adequately validate or escape parameters passed to system-level calls, allowing an attacker to inject shell metacharacters or command delimiters.\nWhen a request is submitted to the affected endpoint, the application incorrectly concatenates the input into a command string that is subsequently executed by the underlying host shell. By supplying crafted payloads, an attacker can manipulate the command structure to execute arbitrary system binaries.\nThe attack flow begins with the attacker establishing an authenticated session with the AOS-CX management interface using administrative credentials. Once authenticated, the attacker crafts a malicious HTTP request targeting the vulnerable API component. The payload includes shell-interpreted characters that terminate the legitimate application command and initiate the execution of the attacker's preferred commands.\nBecause the API backend executes these requests with elevated privileges, the injected payloads run with the same permission set as the management service, effectively granting the attacker full control over the AOS-CX operating environment. This bypasses the intended functional restrictions of the management console.\nThe payload behavior is limited only by the privileges assigned to the user account invoking the API and the availability of system binaries on the AOS-CX OS. Potential actions include modifying device configurations, establishing persistent backdoors, executing reconnaissance tools, or interacting with the network stack to facilitate further network attacks.\nPost-exploitation impact is severe, encompassing the potential for complete device takeover, modification of internal state files, and the disruption of critical network services managed by the AOS-CX platform. The exposure is limited to the management interface network segment, which should typically be isolated, but remains a critical point of failure for enterprise network security."
}
CVE-2026-73766: AOS-CX API Command Injection (HIGH Severity, CVSS: 7.2) - Sceawere