Multiple critical vulnerabilities have been discovered in HPE Aruba Network, affecting AOS Controllers, Gateways , and Mobility Conductor.
See also: W3 Total Cache plugin: Vulnerability puts 1 million WordPress sites at risk

Specifically, two vulnerabilities—CVE-2025-23051 and CVE-2025-23052—pose significant security risks, allowing attackers to execute arbitrary code and commands remotely. The flaws affect multiple versions of ArubaOS, requiring immediate attention from network administrators and organizations using HPE Aruba Networking solutions.
CVE-2025-23051: Verified Remote Code Execution
This vulnerability exists in the web-based management interface of AOS-8 and AOS-10. It allows an authenticated user to perform parameter injection, potentially replacing arbitrary system files.
HPE recommends restricting access to the CLI and web-based management interfaces to a dedicated Layer 2 segment/VLAN and implementing firewall policies at Layer 3 and above.
CVE-2025-23052: Authenticated Command Injection
This vulnerability in the command line interface (CLI) allows an attacker with authenticated access to execute arbitrary commands with privileged user rights on the underlying operating system.
As with CVE-2025-23051, HPE recommends restricting access to the CLI and web-based management interface to secure VLANs and enforcing strong firewall.
See also: Google OAuth “Sign in with Google” vulnerability exposes millions of accounts

The vulnerabilities affect the following HPE Aruba Networking products:
- Mobility Conductor
- Mobility Controllers
- WLAN and SD-WAN Gateways managed by HPE Aruba Networking Central
Affected software versions
- AOS-10.4.xx: 10.4.1.4 and older
- AOS-8.12.xx: 8.12.0.2 and older
- AOS-8.10.xx: 8.10.0.14 and older
These vulnerabilities highlight the importance of proactive security measures in network management systems, such as Aruba. Network administrators are urged to take immediate action by upgrading affected systems and implementing recommended security measures to protect against potential threats.
See also: Juniper Networks patches serious vulnerabilities in Junos OS
Arbitrary code execution vulnerabilities are one of the most serious risks in software security. These vulnerabilities allow an attacker to execute malicious code on the target, bypassing the intended functionality of the program. They typically exploit memory errors, such as buffer overflows or inadequate input checking. The consequences of exploiting these vulnerabilities can include data theft, sensitive information extraction, or even complete compromise . To avoid such security gaps, it is necessary to adopt best programming practices and regularly use security analysis tools.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
