CVE-2026-73768: Local Privilege Escalation in AOS-CX Command Line Interface
Published Sep 1, 2026
·Updated
A vulnerability exists in the command line interface of AOS-CX that may allow for improper processing of malformed input. Successful exploitation could result in the execution of arbitrary commands with root privileges.
Affected Software
1 affected component
AOS-CX Command Line Interface
Event History
Sep 1, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverity
Frequently Asked Questions
1
Is this exposed to unauthenticated remote attackers?
The CVSS vector lists attack vector as local (AV:L), so the provided data does not indicate unauthenticated remote exploitation.
2
What access and conditions are required for exploitation?
The CVSS vector indicates low privileges are required (PR:L) and user interaction is required (UI:R). An attacker would therefore need local access with some existing privileges and would need a user-interaction condition to be met.