CVE-2026-73749: Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
Who can exploit these vulnerabilities?
An unauthenticated remote attacker can exploit them by sending specially crafted packets to the affected service. No prior authentication or user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation could allow remote code execution with elevated privileges, affecting confidentiality, integrity, and availability.
What must be exposed for an environment to be at risk?
The affected AOS-CX daemon service must be reachable by the attacker. The supplied information does not identify the daemon, affected versions, or whether it is enabled by default.