Description
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.
Published: 2026-05-12
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw in the web‑based management interface of AOS‑8 and AOS‑10 allows an attacker who is already authenticated to upload arbitrary files to the underlying operating system, which could lead to execution of those files with privileged rights.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise’s Aruba Networking Wireless Operating System (AOS) versions 8 and 10.

Risk and Exploitability

The flaw carries a CVSS score of 7.2, indicating a high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires remote authenticated access to the web interface; therefore, the attack vector is a remote network‑based, authenticated vector. Given its high severity and the need for valid credentials, the risk is significant for systems that expose the management interface to untrusted networks or have weak access controls.

Generated by OpenCVE AI on May 12, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch the affected AOS firmware to a version that fixes the command injection vulnerability.
  • Restrict the web‑based management interface to a trusted administrative network and enforce strong authentication and role‑based access controls.
  • If an update is unavailable, block the vulnerable endpoints or disable the web interface entirely using firewall rules or host‑based controls.

Generated by OpenCVE AI on May 12, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 14 May 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks arubaos
Arubanetworks sd-wan
CPEs cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks arubaos
Arubanetworks sd-wan

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe arubaos
Vendors & Products Hpe
Hpe arubaos

Tue, 12 May 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Tue, 12 May 2026 19:30:00 +0000

Type Values Removed Values Added
Description Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.
Title Authenticated Remote Code Execution via Arbitrary File Write in AOS-8 and AOS-10 Web-Based Management Interface
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-05-13T15:35:40.376Z

Reserved: 2026-05-07T21:29:03.734Z

Link: CVE-2026-44853

cve-icon Vulnrichment

Updated: 2026-05-13T15:34:42.377Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T20:16:43.913

Modified: 2026-05-14T15:05:17.507

Link: CVE-2026-44853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T10:36:50Z

Weaknesses