Executive brief
Aruba AOS-8 and AOS-10 are operating systems used to manage enterprise network infrastructure like wireless controllers and access points. A security flaw in the management interface allows an administrator to bypass normal restrictions and run unauthorized commands on the device's underlying operating system. This could lead to a complete takeover of the networking hardware, potentially disrupting network operations or allowing further access into the corporate environment.
Technical details
Multiple SQL injection vulnerabilities exist within the underlying service components of Aruba AOS-8 and AOS-10. The flaw is rooted in the improper sanitization of input parameters passed to backend database queries through the command-line interface (CLI) and management protocols. An authenticated attacker with high-level administrative privileges can exploit this by injecting crafted SQL queries. Successful exploitation facilitates a pivot from the database layer to the underlying operating system, allowing for arbitrary command execution (RCE). The vulnerability is tracked as CWE-89 and requires network access to the management interface.
Affected products
- Aruba Networks (HPE) AOS-8
- Aruba Networks (HPE) AOS-10
Timeline
- 2026-05-12: disclosed: Initial disclosure by HPE/Aruba Networks
- 2026-05-12: advisory: NVD record created