CVE-2026-73751: Authenticated Remote Command Injection in AOS-CX Web-based Management Interface
Published Sep 1, 2026
·Updated
An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
Event History
Sep 1, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs an authenticated account with low-privileged access to the web-based management interface. No user interaction is required.
2
What is the potential impact of successful exploitation?
A successful attacker could execute arbitrary commands on the underlying operating system. The reported impact includes high confidentiality, integrity, and availability impact.