HPE Aruba Networking AOS-8 Command Injection Vulnerability in Web-Based Management Interface

Vulnerability

A command injection vulnerability has been identified in the web-based management interface of HPE Aruba Networking AOS-8. This vulnerability allows an authenticated privileged user to modify a package header to inject shell commands, potentially disrupting internal operations. Exploitation of this vulnerability could enable an authenticated malicious actor to execute commands with the privileges of the affected mechanism.

Impact

Successful exploitation allows for arbitrary command execution as a privileged user on the underlying operating system.

Remediation

Users can upgrade to AOS-8.13.1.1 or AOS-8.10.0.21 to address this vulnerability. For more information, visit the HPE Aruba Networking Support Portal.

Added: Jan 13, 2026, 8:54 PM
Updated: Jan 13, 2026, 9:53 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
7.5
exploitability
4.4
remediation
7.9
relevance
2.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.