Executive brief
A vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to upload malicious files and execute commands on the underlying system. This could lead to a complete takeover of the networking device, potentially allowing an attacker to intercept traffic or disrupt network operations.
Technical details
Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw stems from improper neutralization of special elements used in commands within the management UI. An attacker with high-privileged credentials (PR:H) can exploit this over the network without user interaction to upload arbitrary files to the underlying operating system. Successful exploitation allows for remote code execution (RCE) with elevated privileges, granting full control over the affected networking hardware.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory