CVE-2026-23815High· 7.2▾ TwilightA vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized comma…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.9%
Last analysed / modified upstream
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
arubaos-cx < 10.10.1180arubaos-cx >= 10.13.0000, < 10.13.1161arubaos-cx >= 10.16.0000, < 10.16.1030arubaos-cx >= 10.17.0000, < 10.17.1001Upgrade past the affected range:
arubaos-cx 10.17.1001Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23814High· 8.8A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remote attacker to inject malicious commands resulting in unwanted behavior.
CVE-2026-73751High· 8.8An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
CVE-2026-73763High· 7.1A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands
CVE-2026-23816High· 7.2A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
CVE-2026-23813Critical· 9.8A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls
CVE-2026-73780High· 8.3A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection