Executive brief
A vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking device, potentially disrupting network operations or allowing access to sensitive traffic.
Technical details
Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw stems from improper neutralization of special elements used in a command. An attacker with high-privileged administrative credentials can exploit this over the network without user interaction. Successful exploitation allows for arbitrary command execution on the underlying operating system with the privileges of the web service, potentially leading to full system compromise. The vulnerability was reported by Hewlett Packard Enterprise (HPE).
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory