CVE-2026-73780: Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must convince a user who is already authenticated to the web-based management interface to interact with a specially crafted URL. The attacker does not need to be authenticated to the interface themselves.
Which sessions are exposed?
The issue affects some certificate-authenticated sessions in the AOS-CX web-based management interface. The provided information does not identify which certificate-authentication configurations or session types are affected.
What could exploitation allow?
Successful exploitation could allow remote unauthenticated attackers to execute arbitrary input against the affected management interface. The reported impact includes high confidentiality, integrity, and availability effects.