Hewlett Packard Enterprise (HPE) Vulnerabilities and Affected Products
Vulnerabilities associated with ArubaOS (AOS).
Products
Clear product- Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central51 vulnerabilities
- ArubaOS (AOS)34 vulnerabilities
- Aruba ClearPass Policy Manager33 vulnerabilities
- EdgeConnect SD-WAN Orchestrator27 vulnerabilities
- HPE Aruba Networking Wireless Operating System (AOS)27 vulnerabilities
- Aruba EdgeConnect Enterprise Software23 vulnerabilities
- AOS-8 Instant and AOS-10 AP18 vulnerabilities
- Aruba Access Points running InstantOS and ArubaOS 1016 vulnerabilities
- Aruba Access Points: 100 Series; 103 Series; 110 Series; 120 Series; 130 Series; 200 Series; 207 Series; 210 Series; 220 Series; 260 Series; 300 Series; 303 Series; 310 Series; 318 Series Hardened Access Points; 320 Series; 330 Series; 340 Series; 370 Series; 500 Series; 510 Series; 530 Series; 550 Series; 630 Series; 650 Series;14 vulnerabilities
- Aruba EdgeConnect Enterprise Orchestration Software13 vulnerabilities
- AOS-CX12 vulnerabilities
- HPE OneView11 vulnerabilities
- HPE Aruba Networking ClearPass Policy Manager10 vulnerabilities
- HPE Aruba Networking EdgeConnect SD-WAN Gateway9 vulnerabilities
- HPE Athonet Core8 vulnerabilities
- HPE StoreOnce Software8 vulnerabilities
- ArubaOS Wi-Fi Controllers and Campus/Remote Access Points7 vulnerabilities
- HPE 3PAR Service Processor7 vulnerabilities
- Aruba OS6 vulnerabilities
- HPE 3PAR StoreServ Management and Core Software Media6 vulnerabilities
- HPE Aruba Networking Access Points, Instant AOS-8, and AOS-106 vulnerabilities
- HPE Aruba Networking AOS6 vulnerabilities
- HPE Aruba Networking AOS-CX5 vulnerabilities
- HPE Aruba Networking EdgeConnect SD-WAN5 vulnerabilities
- HPE Aruba Networking Fabric Composer (AFC)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-23823HIGH | Authenticated Command Injection leads to RCE in AOS-10 CLI CommandA vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability. CWE-77May 12, 2026 | CVSS7.2v3.1 | EPSS0.957% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-23822MEDIUM | Unauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of ServiceA vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to service disruption or reduced availability of the affected system. NOTE: This vulnerability only impacts Access Points running AOS Instant 8.x.x.x CWE-776May 12, 2026 | CVSS5.3v3.1 | EPSS0.263% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-23821HIGH | Inconsistent input filtering allows Authenticated Command Injection in AOS-10 CLIA vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note: Access Points running AOS-8 Instant software are not affected by this vulnerability. CWE-78May 12, 2026 | CVSS7.2v3.1 | EPSS0.616% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-23820HIGH | Inconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLIA vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. CWE-78May 12, 2026 | CVSS7.2v3.1 | EPSS0.555% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-23819HIGH | Error in SSID Processing allows Stored XSS in Web Management InterfaceA vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configuration settings. CWE-79May 12, 2026 | CVSS8.8v3.1 | EPSS0.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37179MEDIUM | Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating SystemMultiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process. CWE-125Jan 13, 2026 | CVSS5.3v3.1 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37178MEDIUM | Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating SystemMultiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process. CWE-125Jan 13, 2026 | CVSS5.3v3.1 | EPSS0.337% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37177MEDIUM | Authenticated Arbitrary File Deletion Vulnerability in AOS-10 or AOS-8 Command Line Interface (CLI)An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system. CWE-552Jan 13, 2026 | CVSS6.5v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37176MEDIUM | Authenticated Command Injection Vulnerability in an AOS-8 operating system's internal workflowA command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism. CWE-77Jan 13, 2026 | CVSS6.5v3.1 | EPSS1.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37175HIGH | Authenticated Arbitrary File Upload Vulnerability in AOS-10 or AOS-8 Web-Based Management InterfaceArbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system. CWE-434Jan 13, 2026 | CVSS7.2v3.1 | EPSS0.447% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37174HIGH | Authenticated Arbitrary File Write Vulnerability in AOS 10 and AOS-8 Web-Based Management InterfaceAuthenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system. CWE-277Jan 13, 2026 | CVSS7.2v3.1 | EPSS0.494% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37173HIGH | Improper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system. CWE-20Jan 13, 2026 | CVSS7.2v3.1 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37172HIGH | Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceAuthenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. CWE-78Jan 13, 2026 | CVSS7.2v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37171HIGH | Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceAuthenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. CWE-78Jan 13, 2026 | CVSS7.2v3.1 | EPSS1.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37170HIGH | Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceAuthenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. CWE-78Jan 13, 2026 | CVSS7.2v3.1 | EPSS1.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37169HIGH | Stack Overflow Vulnerability in AOS-10 Web-Based Management InterfaceA stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system. | CVSS7.2v3.1 | EPSS0.496% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37168HIGH | Unauthenticated Arbitrary File Deletion Vulnerability in AOS-8 Operating SystemArbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in denial-of-service conditions on affected devices. CWE-552Jan 13, 2026 | CVSS8.2v3.1 | EPSS0.397% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37145MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceArbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits. CWE-22Oct 14, 2025 | CVSS4.9v3.1 | EPSS0.418% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37144MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceArbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits. CWE-22Oct 14, 2025 | CVSS4.9v3.1 | EPSS0.418% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37143MEDIUM | Authenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web Interface (Physical Access Required)An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download arbitrary files through carefully constructed exploits. CWE-284Oct 14, 2025 | CVSS4.9v3.1 | EPSS0.355% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37142MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceArbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits. CWE-284Oct 14, 2025 | CVSS4.9v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37141MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceArbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits. CWE-284Oct 14, 2025 | CVSS4.9v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37140MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management InterfaceArbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits. CWE-284Oct 14, 2025 | CVSS4.9v3.1 | EPSS0.326% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37139MEDIUM | Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable BootA vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware. CWE-400Oct 14, 2025 | CVSS6.0v3.1 | EPSS0.134% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-37138MEDIUM | Authenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required)An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system. CWE-77Oct 14, 2025 | CVSS6.2v3.1 | EPSS0.677% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |