CVE-2025-37132
- EPSS 0.05%
- Veröffentlicht 14.10.2025 16:53:16
- Zuletzt bearbeitet 12.11.2025 16:35:17
An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitra...
CVE-2025-37148
- EPSS 0.06%
- Veröffentlicht 14.10.2025 16:43:35
- Zuletzt bearbeitet 14.10.2025 20:15:36
A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network service...
CVE-2025-37147
- EPSS 0.01%
- Veröffentlicht 14.10.2025 16:42:57
- Zuletzt bearbeitet 14.10.2025 20:15:36
A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vul...
CVE-2025-37146
- EPSS 0.14%
- Veröffentlicht 14.10.2025 16:42:31
- Zuletzt bearbeitet 14.10.2025 19:35:56
A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrar...
CVE-2024-42507
- EPSS 1.67%
- Veröffentlicht 25.09.2024 01:15:42
- Zuletzt bearbeitet 26.09.2024 13:32:02
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful explo...
CVE-2024-42506
- EPSS 1.67%
- Veröffentlicht 25.09.2024 01:15:42
- Zuletzt bearbeitet 26.09.2024 13:32:02
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful explo...
CVE-2024-42505
- EPSS 1.4%
- Veröffentlicht 25.09.2024 01:15:42
- Zuletzt bearbeitet 26.09.2024 13:32:02
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful explo...
CVE-2024-42503
- EPSS 0.1%
- Veröffentlicht 17.09.2024 18:15:04
- Zuletzt bearbeitet 20.09.2024 12:30:51
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.
CVE-2024-42502
- EPSS 0.24%
- Veröffentlicht 17.09.2024 18:15:04
- Zuletzt bearbeitet 20.09.2024 12:30:51
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system.
CVE-2024-42501
- EPSS 0.15%
- Veröffentlicht 17.09.2024 18:15:04
- Zuletzt bearbeitet 20.09.2024 12:30:51
An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating system, enabling the threat actor to execute arbitrary co...