跳到主要内容
CodeAuditAgent

CVE-2026-73778

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.

弱点类型

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.

受影响产品

  • hpe arubaos-cx
  • hpe aruba_cx_10000-48y6c_\(r8p13a\)
  • hpe aruba_cx_10000-48y6c_\(r8p14a\)
  • hpe aruba_cx_10000-48y6c_\(s0f98a\)
  • hpe aruba_cx_10040_\(s4r58a\)
  • hpe aruba_cx_10040_32p_\(s4r54a\)
  • hpe aruba_cx_10040_32p_\(s4r55a\)
  • hpe aruba_cx_10040_32p_\(s4r56a\)

参考链接

赶在攻击者之前发现漏洞。

使用 GitHub 登录,一分钟内即可运行你的第一次审计。免费版无需信用卡。