Executive brief
A vulnerability exists in the web management interface of HPE Aruba Networking AOS-8 and AOS-10 operating systems, which are used to manage enterprise network infrastructure. An authorized administrator could exploit this flaw to run unauthorized commands on the underlying system. This could lead to a complete takeover of the networking device, potentially resulting in network outages or unauthorized access to sensitive data.
Technical details
Command injection vulnerabilities exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw is reachable over the network and requires high-privileged authentication (PR:H) to exploit. By submitting specially crafted input to the management interface, an attacker can bypass input validation to execute arbitrary system-level commands. This grants the attacker full control over the underlying operating system with the privileges of the web service. HPE has released an advisory (hpesbnw05048en_us) detailing the affected versions and necessary updates.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory