HomeSecurityHPE Aruba network vulnerabilities allow arbitrary code execution

HPE Aruba network vulnerabilities allow arbitrary code execution

Multiple critical vulnerabilities have been discovered in HPE Aruba Network, affecting AOS Controllers, Gateways , and Mobility Conductor.

See also: W3 Total Cache plugin: Vulnerability puts 1 million WordPress sites at risk

Aruba Vulnerabilities

Specifically, two vulnerabilities—CVE-2025-23051 and CVE-2025-23052—pose significant security risks, allowing attackers to execute arbitrary code and commands remotely. The flaws affect multiple versions of ArubaOS, requiring immediate attention from network administrators and organizations using HPE Aruba Networking solutions.

CVE-2025-23051: Verified Remote Code Execution
This vulnerability exists in the web-based management interface of AOS-8 and AOS-10. It allows an authenticated user to perform parameter injection, potentially replacing arbitrary system files.

HPE recommends restricting access to the CLI and web-based management interfaces to a dedicated Layer 2 segment/VLAN and implementing firewall policies at Layer 3 and above.

CVE-2025-23052: Authenticated Command Injection
This vulnerability in the command line interface (CLI) allows an attacker with authenticated access to execute arbitrary commands with privileged user rights on the underlying operating system.

As with CVE-2025-23051, HPE recommends restricting access to the CLI and web-based management interface to secure VLANs and enforcing strong firewall.

See also: Google OAuth “Sign in with Google” vulnerability exposes millions of accounts

HPE Aruba network vulnerabilities allow arbitrary code execution

The vulnerabilities affect the following HPE Aruba Networking products:

  • Mobility Conductor
  • Mobility Controllers
  • WLAN and SD-WAN Gateways managed by HPE Aruba Networking Central

Affected software versions

  • AOS-10.4.xx: 10.4.1.4 and older
  • AOS-8.12.xx: 8.12.0.2 and older
  • AOS-8.10.xx: 8.10.0.14 and older

These vulnerabilities highlight the importance of proactive security measures in network management systems, such as Aruba. Network administrators are urged to take immediate action by upgrading affected systems and implementing recommended security measures to protect against potential threats.

See also: Juniper Networks patches serious vulnerabilities in Junos OS

Arbitrary code execution vulnerabilities are one of the most serious risks in software security. These vulnerabilities allow an attacker to execute malicious code on the target, bypassing the intended functionality of the program. They typically exploit memory errors, such as buffer overflows or inadequate input checking. The consequences of exploiting these vulnerabilities can include data theft, sensitive information extraction, or even complete compromise . To avoid such security gaps, it is necessary to adopt best programming practices and regularly use security analysis tools.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS