HPE Aruba Networking AOS-8 Command Injection Vulnerability in Mobility Conductors

Vulnerability

A command injection vulnerability has been identified in the web-based management interface of HPE Aruba Networking mobility conductors running the AOS-8 operating system. This vulnerability allows authenticated malicious actors to execute arbitrary commands as privileged users on the underlying operating system.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution with elevated privileges on the affected system's operating system.

Remediation

To address this vulnerability, upgrade to AOS-8.13.1.1 or above. For versions prior to AOS-8.13.1.1, consult the HPE Aruba Networking Support Portal for available updates.

Added: Jan 13, 2026, 10:08 PM
Updated: Jan 13, 2026, 10:08 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
7.5
exploitability
4.4
remediation
7.9
relevance
2.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.