SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-73780

HIGH · CVSS 8.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-07

CyberRota Analysis

AI-Generated

The web-based management interface of AOS-CX switches is vulnerable due to insufficient Cross-Site Request Forgery (CSRF) protection, enabling remote unauthenticated attackers to execute arbitrary commands by tricking authenticated users into clicking malicious links. This vulnerability poses a high risk, as it could lead to unauthorized access and manipulation of switch configurations. Organizations using AOS-CX switches should prioritize remediation to safeguard their network infrastructure against potential exploitation.

CVE
CVE-2026-73780
Severity
HIGH
CVSS
8.3
EPSS
0.13%

Original NVD Description

A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.

Related CVEs

Other vulnerabilities affecting the same vendor(s)