Executive brief
A security vulnerability has been identified in the operating systems used by HPE Aruba networking devices. This flaw exists in the command line interface service, which is used by administrators to manage network hardware. If exploited, a remote attacker with administrative credentials could take full control of the device, potentially leading to data theft or significant network disruption.
Technical details
This vulnerability is classified as a command injection (CWE-77) within the Command Line Interface (CLI) service of HPE Aruba AOS-8 and AOS-10. The flaw is accessible via the Process Application Programming Interface (PAPI) protocol. An attacker requires network reachability and high-privileged authentication (PR:H) to exploit the vulnerability. Successful exploitation allows for the execution of arbitrary commands with the privileges of the underlying operating system, bypassing intended CLI restrictions. HPE has released an advisory (hpesbnw05048en_us) detailing the affected versions and necessary updates.
Affected products
- HPE Aruba Networking AOS-8
- HPE Aruba Networking AOS-10
Timeline
- 2026-05-12: disclosed: Initial disclosure by HPE
- 2026-05-12: advisory: NVD publication date