CVE-2025-25040Low· 3.3▾ SunlitA vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects: - AOS-CX 10.14.xxxx : All patches - AOS-CX 10.15.xxxx : 10.15.10…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 18.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
A vulnerability has been identified in the port ACL functionality of AOS-CX software running on the HPE Aruba Networking CX 9300 Switch Series only and affects:
- AOS-CX 10.14.xxxx : All patches
- AOS-CX 10.15.xxxx : 10.15.1000 and below
The vulnerability is specific to traffic originated by the CX 9300 switch platform and could allow an attacker to bypass ACL rules applied to routed ports on egress. As a result, port ACLs are not correctly enforced, which could lead to unauthorized traffic flow and violations of security policies. Egress VLAN ACLs and Routed VLAN ACLs are not affected by this vulnerability.
arubaos-cx >= 10.14.0000, < 10.14.1040arubaos-cx >= 10.15.0000, < 10.15.1001Upgrade past the affected range:
arubaos-cx 10.15.1001Connected by shared product, vendor, weakness, or advisory.
CVE-2024-54010Low· 3.4A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists
CVE-2026-73780High· 8.3A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection
CVE-2026-73759Medium· 6.5Vulnerabilities in AOS-CX could allow an unauthenticated remote malicious actor to trigger a denial-of-service condition by sending specially crafted packets
CVE-2026-73752High· 8.8An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX
CVE-2026-73749Critical· 9.8Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input
CVE-2026-73751High· 8.8An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.