VendorsAruba Networksap-635any version
Vulnerabilities

Aruba Networks Ap-635 - any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2022-37888
There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these vulnerabilities results in the ability to execute arbitrary code as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.
Published 2022-10-06 · Modified
9.8EPSS 0.017
CVE-2026-23808
Client Isolation Bypass via GTK Manipulation
Published 2026-03-04 · Analyzed
8.1EPSS 0.003
CVE-2026-23809
MAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic Redirection
Published 2026-03-04 · Analyzed
7.6EPSS 0.003
CVE-2026-23601
Frame Injection via Shared GTK Allows Traffic Spoofing and Client Compromise
Published 2026-03-04 · Analyzed
5.4EPSS 0.001
CVE-2026-23810
Cross-BSSID GTK Re-encryption and Traffic Injection
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23811
Unauthorized Bi-Directional Traffic Interception via L2/L3 Manipulation
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23812
Security Boundary Bypass via Routing Node Impersonation
Published 2026-03-04 · Analyzed
4.3EPSS 0.001