HPE Aruba Networking AOS-8 Unauthenticated Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing unauthenticated remote file deletion has been identified in HPE Aruba Networking's AOS-8 operating system, specifically within the Mobility Conductors, Controllers, and certain Gateways. Successful exploitation could enable a remote malicious actor to delete arbitrary files on the affected system, potentially leading to denial-of-service conditions on the device.

Impact

Exploitation of this vulnerability could result in unauthorized deletion of files, with a possibility of causing denial-of-service conditions on the affected device.

Remediation

Users are advised to upgrade to AOS-8.13.1.1 or AOS-8.10.0.21 and above. For versions with available patches, instructions can be found on the HPE Networking Support Portal.

Added: Jan 13, 2026, 9:58 PM
Updated: Jan 13, 2026, 9:58 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
7.0
remediation
7.9
relevance
2.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.