Executive brief
A vulnerability in the web management interface of HPE Aruba Networking operating systems (AOS-8 and AOS-10) could allow an authorized administrator to execute unauthorized commands on the underlying system. If exploited, an attacker with administrative credentials could gain full control over the networking hardware, potentially leading to data interception or network-wide service disruptions. This issue affects the software used to manage enterprise wireless and wired network controllers.
Technical details
Command injection vulnerabilities (CWE-77) exist within the web-based management interface of HPE Aruba Networking AOS-8 and AOS-10. The flaw is rooted in improper neutralization of special elements used in commands within the web UI. An attacker must be authenticated with high privileges (PR:H) to reach the vulnerable component. Successful exploitation allows for arbitrary command execution on the underlying Linux-based operating system with the privileges of the web service. Users are advised to refer to the HPE Aruba Networking security advisory for specific patched firmware versions.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory