CVE-2026-73782: Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX
Published Sep 1, 2026
·Updated
A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Affected Software
1 affected component
AOS-CX
Event History
Sep 1, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is rated adjacent-network accessible and does not require privileges or user interaction. Exploitation targets the AOS-CX command line interface.
2
What could an attacker do after successful exploitation?
A successful exploit can result in arbitrary code execution as a privileged user on the underlying operating system. This can affect confidentiality, integrity, and availability.