Executive brief
A security vulnerability has been identified in the management interface of HPE Aruba Networking Access Points, which provide wireless connectivity for corporate environments. An authorized user with administrative access could bypass security restrictions to run unauthorized commands on the device's underlying operating system. This could lead to a complete takeover of the access point, potentially allowing an attacker to disrupt network services or intercept traffic.
Technical details
A command injection vulnerability (CWE-77) exists in the Command Line Interface (CLI) of HPE Aruba Networking Access Points running AOS-10.7.x.x and above. The flaw is caused by improper neutralization of special elements within CLI inputs, allowing an attacker to escape the restricted shell. Exploitation requires network reachability to the management interface and high-privilege authentication (PR:H). If successful, a remote attacker can execute arbitrary system-level commands with the privileges of the underlying operating system, leading to full compromise of the device. Older versions such as AOS-10.4 and AOS-8 Instant are reportedly not affected.
Affected products
- HPE Aruba Networking AOS-10 Access Points 10.7.x.x and above
Timeline
- 2026-05-12: disclosed: Initial advisory publication by HPE and NVD