HPE Aruba Networking AirWave Command Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking AirWave Platform, affecting versions 8.3.0.4 and below. This vulnerability allows authenticated attackers to execute arbitrary operating system commands with elevated privileges on the underlying operating system.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands with elevated privileges, allowing for arbitrary code execution on the affected system.

Remediation

Users are advised to upgrade to HPE Aruba Networking Management Software (AirWave) version 8.3.0.5 or above. The updated version is available for download from the HPE Networking Support Portal.

Added: Nov 18, 2025, 7:27 PM
Updated: Nov 18, 2025, 7:27 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
7.5
exploitability
4.8
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.