CVE-2026-63454

Summary

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)AOS-CX10.17.0000 <= 10.17.1020affected
Hewlett Packard Enterprise (HPE)AOS-CX10.16.0000 <= 10.16.1050affected
Hewlett Packard Enterprise (HPE)AOS-CX10.13.0000 <= 10.13.1180affected
Hewlett Packard Enterprise (HPE)AOS-CX10.18.0000 < 10.18.0001affected

Weaknesses

References