What happened
An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.
Affected versions
AOS-CX: 10.18.0000 through 10.18.0001 (semver); 10.17.0000 through 10.17.1021 (semver); 10.16.0000 through 10.16.1051 (semver); 10.13.0000 through 10.13.1180 (semver); 10.10.0000 through 10.10.1180 (semver) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.