Executive brief
Aruba AOS-8 and AOS-10 are operating systems used to manage enterprise network infrastructure such as wireless controllers and access points. A security flaw in the management interface allows an administrator to run unauthorized commands on the underlying system. While this requires existing administrative access, it could allow a malicious insider or a compromised admin account to take full control of the networking hardware and disrupt operations.
Technical details
Multiple SQL injection vulnerabilities exist within the service components of Aruba AOS-8 and AOS-10. These flaws are accessible via the Command-Line Interface (CLI) and management protocols. The root cause is the failure to sanitize input parameters before passing them to backend database queries (CWE-89). An attacker must have authenticated administrative privileges to exploit these vulnerabilities. Successful exploitation allows for a pivot from SQL injection to arbitrary command execution on the underlying operating system, leading to a full compromise of the device's confidentiality, integrity, and availability.
Affected products
- Aruba Networks (HPE) AOS-8
- Aruba Networks (HPE) AOS-10
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory