Executive brief
A security vulnerability has been identified in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems. An authorized user with administrative access could exploit a flaw in the certificate download feature to overwrite system files and take full control of the device. This could lead to a complete compromise of the networking hardware, allowing an attacker to disrupt operations or intercept data.
Technical details
An authenticated remote code execution (RCE) vulnerability exists in the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw is located within the certificate download functionality, where improper input validation of the file path parameter allows for arbitrary file overwrite. An attacker with high privileges (PR:H) can leverage this to overwrite critical system files and execute arbitrary commands on the underlying operating system with privileged access. The attack is reachable over the network (AV:N) and requires no user interaction.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory