Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73781— Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management Interface

Quick assessment

Affected
Hewlett Packard Enterprise (HPE) AOS-CX
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hewlett Packard Enterprise AOS-CX是美国Hewlett Packard Enterprise公司的一款网络交换机操作系统。 Hewlett Packard Enterprise AOS-CX 10.18.0001及之前的10.18.x版本、10.17.1021及之前的10.17.x版本、10.16.1051及之前的10.16.x版本、10.13.1180及之前的10.13.x版本和10.10.1180及之前的10.10.x版本存在安全漏洞,该漏洞源于基于Web的管理界面存在

CVSS 8.4 · High EPSS 0.28% · P21

Possible ATT&CK Techniques 1 AI

T1059.007 · JavaScript

Affected Version Matrix 5

VendorProduct Version RangeStatus
Hewlett Packard Enterprise (HPE) AOS-CX 10.18.0000≤ 10.18.0001 affected
10.17.0000≤ 10.17.1021 affected
10.16.0000≤ 10.16.1051 affected
10.13.0000≤ 10.13.1180 affected
10.10.0000≤ 10.10.1180 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73781

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management Interface
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Hewlett Packard Enterprise AOS-CX 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Hewlett Packard Enterprise AOS-CX是美国Hewlett Packard Enterprise公司的一款网络交换机操作系统。 Hewlett Packard Enterprise AOS-CX 10.18.0001及之前的10.18.x版本、10.17.1021及之前的10.17.x版本、10.16.1051及之前的10.16.x版本、10.13.1180及之前的10.13.x版本和10.10.1180及之前的10.10.x版本存在安全漏洞,该漏洞源于基于Web的管理界面存在
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Hewlett Packard Enterprise (HPE) AOS-CX 10.18.0000 ~ 10.18.0001 -

II. Public POCs for CVE-2026-73781

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73781

登录查看更多情报信息。

Same Patch Batch · Hewlett Packard Enterprise (HPE) · 2026-09-01 · 86 CVEs total

CVE-2026-76658 10.0 CRITICAL Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon
CVE-2026-76657 10.0 CRITICAL Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access
CVE-2026-73749 9.8 CRITICAL Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
CVE-2026-19766 9.6 CRITICAL Authentication Bypass leads to Administrative control of adjacent network hosts in HPE Net
CVE-2026-73701 9.0 CRITICAL Unauthenticated Remote Code Execution in HPE Networking Fabric Composer
CVE-2026-73700 9.0 CRITICAL Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in HPE Networking Fabric Com
CVE-2026-73702 8.8 HIGH Authenticated Privilege Escalation Vulnerability in the API of HPE Networking Fabric Compo
CVE-2026-73703 8.8 HIGH Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in HPE Networking Fabric C
CVE-2026-73704 8.8 HIGH Authenticated Command Injection Leading to Administrative Access in HPE Networking Fabric
CVE-2026-73705 8.8 HIGH Authenticated Arbitrary File Write leads to Remote Code Execution in HPE Networking Fabric
CVE-2026-73782 8.8 HIGH Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX
CVE-2026-73750 8.8 HIGH Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Cod
CVE-2026-73751 8.8 HIGH Authenticated Remote Command Injection in AOS-CX Web-based Management Interface
CVE-2026-73752 8.8 HIGH Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-C
CVE-2026-73753 8.8 HIGH Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface
CVE-2026-73706 8.6 HIGH Authentication Bypass in the API of HPE Networking Fabric Composer allows Data Exposure an
CVE-2026-73707 8.5 HIGH Authenticated Privilege Escalation via Broken Access Control in HPE Networking Fabric Comp
CVE-2026-73780 8.3 HIGH Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessio
CVE-2026-73709 8.3 HIGH Unauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation P
CVE-2026-73708 8.3 HIGH Fault in Business Logic allows Authenticated Sensitive Information Disclosure in HPE Netwo

Showing top 20 of 86 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-73781

No comments yet


Leave a comment