CVE-2026-73752: Unauthenticated Arbitrary File Write Vulnerability Leads to Remote Code Execution in AOS-CX
Published Sep 1, 2026
·Updated
An unauthenticated arbitrary file write vulnerability exists in an API endpoint of AOS-CX. Successful exploitation of this vulnerability allows an attacker to write arbitrary files to the underlying operating system, which could lead to remote code execution.
Affected Software
1 affected component
AOS-CX
Event History
Sep 1, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication or prior privileges are required. The vulnerable API endpoint can be exploited by an unauthenticated attacker.
2
What could exploitation allow an attacker to do?
An attacker can write arbitrary files to the underlying operating system. This may lead to remote code execution and impact confidentiality, integrity, and availability.