HPE Aruba Networking AOS-8 and AOS-10 Improper Input Handling Vulnerability in Web-Based Management Interface

Vulnerability

A vulnerability allowing improper input handling has been identified in the web-based management interface of HPE Aruba Networking mobility conductors, controllers, and gateways running AOS-10 or AOS-8. This vulnerability could be exploited by an authenticated malicious actor with valid credentials to cause unintended behavior on the affected system.

Impact

Exploitation of this vulnerability could lead to arbitrary command execution, unauthorized write access to the file system, or other unintended behaviors, depending on the specific context of the exploitation.

Remediation

To address this vulnerability, HPE Aruba Networking recommends upgrading to AOS-10.7.2.2 and above, AOS-10.4.1.10 and above, AOS-8.13.1.1 and above, or AOS-8.10.0.21 and above. These updates can be downloaded from the HPE Networking Support Portal.

Added: Jan 13, 2026, 8:57 PM
Updated: Jan 13, 2026, 8:57 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
0.6
exploitability
4.9
remediation
7.9
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.