VDB
GCVE-110-NCSC-2026-340
GCVE-110-NCSC-2026-340
Advisory PublishedCVSS 4.9/10
Multiple vulnerabilities in an AOS-CX daemon enable an unauthenticated remote attacker to send crafted packets that may result in remote code execution with elevated privileges.
Weaknesses (CWE)
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-134Use of Externally-Controlled Format StringCWE-352Cross-Site Request Forgery (CSRF)CWE-521Weak Password RequirementsCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-73External Control of File Name or PathCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-125Out-of-bounds ReadCWE-918Server-Side Request Forgery (SSRF)CWE-121Stack-based Buffer Overflow
Risk Scores
CVSS 3.1
4.9/10
Medium · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| HPE | vers:unknown/* | — | — |
| Aruba Networks | vers:unknown/* | — | — |
Aliases
CVE-2026-73749CVE-2026-73750CVE-2026-73751CVE-2026-73752CVE-2026-73753CVE-2026-73754CVE-2026-73755CVE-2026-73757CVE-2026-73758CVE-2026-73760CVE-2026-73761CVE-2026-73762CVE-2026-73763CVE-2026-73764CVE-2026-73770CVE-2026-73772CVE-2026-73773CVE-2026-73774CVE-2026-73775CVE-2026-73776CVE-2026-73777CVE-2026-73778CVE-2026-73779CVE-2026-73780CVE-2026-73782CVE-2026-73783
Browse GCVE Records
3,521 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.