Description
A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on affected Access Points.
Scores
CVSS v3
7.1
EPSS
0.0002
EPSS Percentile
3.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-290
Status
published
Products (5)
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS)
10.4.0.0 - 10.4.1.8
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS)
10.7.0.0 - 10.7.1.1
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS)
8.10.0.0 - 8.10.0.18
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS)
8.12.0.0 - 8.12.0.5
Hewlett Packard Enterprise (HPE)/ArubaOS (AOS)
8.13.0.0 - 8.13.0.1
Published
Oct 14, 2025
Tracked Since
Feb 18, 2026