HPE Aruba Networking AOS-10 and AOS-8 Web Management Interface Arbitrary File Write Vulnerability Allowing Remote Code Execution

Vulnerability

A vulnerability allowing arbitrary file writes has been identified in the web-based management interface of HPE Aruba Networking AOS-10 Gateways and AOS-8 Controller/Mobility Conductor operating systems. This vulnerability could be exploited by an authenticated attacker to upload arbitrary files and execute commands on the underlying operating system.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, allowing for arbitrary file writes on the system. This could be used to execute malicious commands, potentially compromising the system's integrity and availability.

Remediation

Users are advised to upgrade to AOS-10.7.2.1 and above, AOS-10.4.1.9 and above, AOS-8.13.1.0 and above, AOS-8.12.0.6 and above, or AOS-8.10.0.19 and above. These versions include patches for the vulnerability. The updated software can be downloaded from the HPE Networking Support Portal.

Added: Oct 14, 2025, 5:46 PM
Updated: Oct 14, 2025, 10:39 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
10.0
exploitability
4.9
remediation
7.9
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.