Description
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.
Published: 2026-05-12
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw in the web‑based management interface of AOS‑8 and AOS‑10 allows an attacker who is already authenticated to upload arbitrary files to the underlying operating system, which could lead to execution of those files with privileged rights.

Affected Systems

The vulnerability affects Hewlett Packard Enterprise’s Aruba Networking Wireless Operating System (AOS) versions 8 and 10.

Risk and Exploitability

The flaw carries a CVSS score of 7.2, indicating a high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Successful exploitation requires remote authenticated access to the web interface; therefore, the attack vector is a remote network‑based, authenticated vector. Given its high severity and the need for valid credentials, the risk is significant for systems that expose the management interface to untrusted networks or have weak access controls.

Generated by OpenCVE AI on May 12, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch the affected AOS firmware to a version that fixes the command injection vulnerability.
  • Restrict the web‑based management interface to a trusted administrative network and enforce strong authentication and role‑based access controls.
  • If an update is unavailable, block the vulnerable endpoints or disable the web interface entirely using firewall rules or host‑based controls.

Generated by OpenCVE AI on May 12, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Tue, 12 May 2026 19:30:00 +0000

Type Values Removed Values Added
Description Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.
Title Authenticated Remote Code Execution via Arbitrary File Write in AOS-8 and AOS-10 Web-Based Management Interface
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-05-12T18:56:48.717Z

Reserved: 2026-05-07T21:29:03.734Z

Link: CVE-2026-44853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-12T20:16:43.913

Modified: 2026-05-12T20:16:43.913

Link: CVE-2026-44853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T20:45:23Z

Weaknesses