Executive brief
A security vulnerability exists in the software used to manage certain Aruba wireless access points. An attacker with administrative credentials could exploit this flaw to run unauthorized commands on the device's operating system. This could lead to a complete takeover of the access point, potentially allowing the attacker to disrupt network traffic or gain further access to the corporate network.
Technical details
A vulnerability classified as OS Command Injection (CWE-78) exists in the configuration processing logic of Aruba Access Points running AOS-10. The flaw allows a remote attacker with high privileges (PR:H) to inject and execute arbitrary system commands on the underlying Linux-based operating system. The attack is network-reachable and requires no user interaction, though it depends on certain pre-existing configuration conditions. Access points running AOS-8 Instant software are explicitly noted as not being affected by this issue.
Affected products
- Aruba (HPE) AOS-10 AOS-10 (all versions)
Timeline
- 2026-05-12: advisory: Initial disclosure by HPE/Aruba