VendorsAruba Networksarubaosall versions
Vulnerabilities

Aruba Networks ArubaOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

233CVEs
CVE-2022-37901
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
CVE-2022-37902
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.017
CVE-2023-22758
Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Published 2023-02-28 · Modified
7.2EPSS 0.016
CVE-2023-22759
Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Published 2023-02-28 · Modified
7.2EPSS 0.016
CVE-2023-22760
Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Published 2023-02-28 · Modified
7.2EPSS 0.016
CVE-2023-22761
Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Published 2023-02-28 · Modified
7.2EPSS 0.016
CVE-2023-35972
Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Published 2023-07-05 · Modified
7.2EPSS 0.016
CVE-2026-44853
Authenticated Remote Code Execution via Arbitrary File Write in AOS-8 and AOS-10 Web-Based Management Interface
Published 2026-05-12 · Analyzed
7.2EPSS 0.016
CVE-2026-44854
Authenticated Remote Code Execution via Arbitrary File Write in AOS-8 and AOS-10 Web-Based Management Interface
Published 2026-05-12 · Analyzed
7.2EPSS 0.016
CVE-2023-22762
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22763
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22764
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22765
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22766
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22767
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22768
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22769
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2023-22770
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-02-28 · Modified
7.2EPSS 0.015
CVE-2022-37898
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2022-11-03 · Modified
7.2EPSS 0.015
CVE-2026-44865
Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Published 2026-05-12 · Analyzed
7.2EPSS 0.015
CVE-2025-37176
Authenticated Command Injection Vulnerability in an AOS-8 operating system's internal workflow
Published 2026-01-13 · Analyzed
7.2EPSS 0.014
CVE-2025-37171
Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface
Published 2026-01-13 · Analyzed
7.2EPSS 0.014
CVE-2023-35973
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-07-05 · Modified
7.2EPSS 0.014
CVE-2023-35974
Authenticated Remote Command Execution in the ArubaOS Command Line Interface
Published 2023-07-05 · Modified
7.2EPSS 0.014
CVE-2025-37170
Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface
Published 2026-01-13 · Analyzed
7.2EPSS 0.013
CVE-2025-37172
Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface
Published 2026-01-13 · Analyzed
7.2EPSS 0.013
CVE-2024-1356
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-03-05 · Analyzed
7.2EPSS 0.012
CVE-2024-25611
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-03-05 · Analyzed
7.2EPSS 0.012
CVE-2024-25612
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-03-05 · Analyzed
7.2EPSS 0.012
CVE-2024-25613
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Published 2024-03-05 · Analyzed
7.2EPSS 0.012
CVE-2025-37134
Authenticated Command Injection Vulnerability in the Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Published 2025-10-14 · Analyzed
7.2EPSS 0.012
CVE-2025-37133
Authenticated Command Injection Vulnerability in AOS-8 Controller/Mobility Conductor Web-Based Management Interface via the CLI Binaryalong with accounting controls for tracking and logging user activities and resource usage.
Published 2025-10-14 · Analyzed
7.2EPSS 0.012
CVE-2026-44872
Authenticated Arbitrary File Upload via Command Injection in AOS-8 AND AOS-10 Web-Based Management Interface
Published 2026-05-12 · Analyzed
7.2EPSS 0.012
CVE-2025-27083
Authenticated Command Injection Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Published 2025-04-08 · Analyzed
7.2EPSS 0.012
CVE-2015-1388
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.
Published 2015-03-24 · Modified
7.2EPSS 0.011
CVE-2026-23823
Authenticated Command Injection leads to RCE in AOS-10 CLI Command
Published 2026-05-12 · Analyzed
7.2EPSS 0.010
CVE-2023-45626
An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.
Published 2023-11-14 · Modified
7.2EPSS 0.009
CVE-2023-22773
Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.
Published 2023-02-28 · Modified
7.2EPSS 0.008
CVE-2023-22774
Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion.
Published 2023-02-28 · Modified
7.2EPSS 0.008
CVE-2026-44857
Authenticated Stack-Based Buffer Overflow in PAPI Services
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
← Prev4 / 6Next →