CVE-2025-27084
- EPSS 0.12%
- Veröffentlicht 08.04.2025 16:32:46
- Zuletzt bearbeitet 12.11.2025 20:14:34
A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitra...
CVE-2025-27085
- EPSS 0.26%
- Veröffentlicht 08.04.2025 16:29:25
- Zuletzt bearbeitet 12.11.2025 20:27:45
Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from...
CVE-2025-27083
- EPSS 0.57%
- Veröffentlicht 08.04.2025 16:26:50
- Zuletzt bearbeitet 12.11.2025 19:14:51
Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary comm...
CVE-2025-27082
- EPSS 0.44%
- Veröffentlicht 08.04.2025 16:22:50
- Zuletzt bearbeitet 12.11.2025 19:18:28
Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files ...
CVE-2024-47463
- EPSS 1.4%
- Veröffentlicht 05.11.2024 23:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote...
CVE-2024-42509
- EPSS 2.61%
- Veröffentlicht 05.11.2024 23:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploit...
- EPSS 1.94%
- Veröffentlicht 05.11.2024 23:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploit...
CVE-2024-47461
- EPSS 0.24%
- Veröffentlicht 05.11.2024 23:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlyin...
CVE-2024-47462
- EPSS 1.4%
- Veröffentlicht 05.11.2024 23:15:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote...
CVE-2024-42505
- EPSS 1.4%
- Veröffentlicht 25.09.2024 01:15:42
- Zuletzt bearbeitet 15.04.2026 00:35:42
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful explo...