Executive brief
A security vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking equipment, potentially allowing an attacker to intercept traffic or disrupt network operations.
Technical details
Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw is rooted in the improper neutralization of special elements used in commands within the web UI. An attacker with high-privileged administrative credentials can exploit this over the network without user interaction. Successful exploitation allows for arbitrary command execution on the underlying Linux-based operating system, potentially leading to full system compromise. Users are advised to refer to the HPE security advisory for specific patched firmware versions.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed: Initial disclosure by HPE
- 2026-05-12: advisory: NVD publication date