CVE-2025-27084Cross-site Scripting in Arubaos

Severity
6.1MEDIUMNVD
CNA5.4
EPSS
0.1%
top 69.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8

Description

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDarubanetworks/arubaos8.10.0.08.10.0.16+3
CVEListV5hewlett_packard_enterprise/hpe_aruba_networking_aos10.7.0.010.7.1.0+3

🔴Vulnerability Details

2
GHSA
GHSA-q7p5-2w2c-9c56: A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cro2025-04-08
CVEList
Reflected Cross-Site Scripting (XSS) Vulnerability in Captive Portal (CP) of an AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-based Management Interface2025-04-08
CVE-2025-27084 — Cross-site Scripting in Arubaos | cvebase