Executive brief
HPE Aruba Networking AOS-8 and AOS-10 operating systems, which power enterprise network controllers and access points, are affected by security vulnerabilities in their management interface. An attacker who already has administrative access to the system's command-line interface could exploit these flaws to take full control of the underlying operating system. This could lead to a complete compromise of the networking hardware and the data passing through it.
Technical details
Multiple stack-based buffer overflow vulnerabilities (CWE-121) exist within the management service components of HPE Aruba Networking AOS-8 and AOS-10. The flaws are reachable via the command-line interface (CLI). An attacker must be authenticated with high administrative privileges to reach the vulnerable code paths. By sending specially crafted requests to these services, an attacker can trigger the overflow to achieve arbitrary code execution with elevated privileges on the underlying Linux-based operating system. The vulnerability is tracked as CVE-2026-44856 with a CVSS score of 7.2.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory