Arubanetworks Arubaos vulnerabilities
231 known vulnerabilities affecting arubanetworks/arubaos.
Total CVEs
231
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL46HIGH123MEDIUM58LOW4
Vulnerabilities
Page 4 of 12
CVE-2022-37904P3HIGHCVSS 8.8≥ 6.5.4.0, < 6.5.4.22≥ 8.4.0.0, < 8.6.0.17+3 more2022-12-12
CVE-2022-37904 [HIGH] CWE-123 CVE-2022-37904: Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execu
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
nvd
CVE-2026-44865P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44865 [HIGH] CWE-77 CVE-2026-44865: Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Op
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2025-37171P3HIGHCVSS 7.2≥ 8.6.0.0, < 8.10.0.21≥ 8.11.0.0, < 8.13.1.12026-01-13
CVE-2025-37171 [HIGH] CWE-78 CVE-2025-37171: Authenticated command injection vulnerabilities exist in the web-based management interface of mobil
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2025-37170P3HIGHCVSS 7.2≥ 8.6.0.0, < 8.10.0.21≥ 8.11.0.0, < 8.13.1.12026-01-13
CVE-2025-37170 [HIGH] CWE-78 CVE-2025-37170: Authenticated command injection vulnerabilities exist in the web-based management interface of mobil
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2025-37172P3HIGHCVSS 7.2≥ 8.6.0.0, < 8.10.0.21≥ 8.11.0.0, < 8.13.1.12026-01-13
CVE-2025-37172 [HIGH] CWE-78 CVE-2025-37172: Authenticated command injection vulnerabilities exist in the web-based management interface of mobil
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-44872P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44872 [HIGH] CWE-77 CVE-2026-44872: A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 O
A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device.
nvd
CVE-2026-23823P3HIGHCVSS 7.2≥ 6.4.0.0, ≤ 6.5.4.24≥ 8.4.0.0, < 8.10.0.0+3 more2026-05-12
CVE-2026-23823 [HIGH] CWE-77 CVE-2026-23823: A vulnerability in the command line interface of Access Points running AOS-10 could allow an authent
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AO
nvd
CVE-2026-44859P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44859 [HIGH] CWE-121 CVE-2026-44859: Stack-based buffer overflow vulnerabilities exist in several underlying management service component
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Success
nvd
CVE-2026-44856P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44856 [HIGH] CWE-121 CVE-2026-44856: Stack-based buffer overflow vulnerabilities exist in several underlying management service component
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Success
nvd
CVE-2026-44857P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44857 [HIGH] CWE-121 CVE-2026-44857: Stack-based buffer overflow vulnerabilities exist in several underlying management service component
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Success
nvd
CVE-2026-44855P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44855 [HIGH] CWE-121 CVE-2026-44855: Stack-based buffer overflow vulnerabilities exist in several underlying management service component
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Success
nvd
CVE-2026-44858P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44858 [HIGH] CWE-121 CVE-2026-44858: Stack-based buffer overflow vulnerabilities exist in several underlying management service component
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Success
nvd
CVE-2026-23821P3HIGHCVSS 7.2≥ 6.4.0.0, ≤ 6.5.4.24≥ 8.4.0.0, < 8.10.0.0+4 more2026-05-12
CVE-2026-23821 [HIGH] CWE-78 CVE-2026-23821: A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Note: Access Points running AOS-8 Instant
nvd
CVE-2026-44862P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44862 [HIGH] CWE-89 CVE-2026-44862: SQL injection vulnerabilities exist in several underlying service components accessible through the
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database querie
nvd
CVE-2026-44863P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44863 [HIGH] CWE-89 CVE-2026-44863: SQL injection vulnerabilities exist in several underlying service components accessible through the
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database querie
nvd
CVE-2026-44864P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44864 [HIGH] CWE-89 CVE-2026-44864: SQL injection vulnerabilities exist in several underlying service components accessible through the
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database querie
nvd
CVE-2026-44860P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44860 [HIGH] CWE-89 CVE-2026-44860: SQL injection vulnerabilities exist in several underlying service components accessible through the
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database querie
nvd
CVE-2026-44861P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.22≥ 8.11.0.0, < 8.12.0.7+3 more2026-05-12
CVE-2026-44861 [HIGH] CWE-89 CVE-2026-44861: SQL injection vulnerabilities exist in several underlying service components accessible through the
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database querie
nvd
CVE-2025-37175P3HIGHCVSS 7.2≥ 6.5.4.0, < 8.10.0.21≥ 8.11.0.0, < 8.13.1.1+2 more2026-01-13
CVE-2025-37175 [HIGH] CWE-434 CVE-2025-37175: Arbitrary file upload vulnerability exists in the web-based management interface of mobility conduct
Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.
nvd
CVE-2026-23819P3HIGHCVSS 8.8≥ 6.4.0.0, ≤ 6.5.4.24≥ 8.4.0.0, < 8.10.0.22+5 more2026-05-12
CVE-2026-23819 [HIGH] CWE-79 CVE-2026-23819: A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Inst
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successful exploitation could allow an attacker to compromise user data and potentially manipulate device configu
nvd