VendorsAruba Networksarubaos10.8.0.0
Vulnerabilities

Aruba Networks ArubaOS 10.8.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-23819
Error in SSID Processing allows Stored XSS in Web Management Interface
Published 2026-05-12 · Analyzed
8.8EPSS 0.003
CVE-2026-23808
Client Isolation Bypass via GTK Manipulation
Published 2026-03-04 · Analyzed
8.1EPSS 0.003
CVE-2026-23809
MAC Address Spoofing leads to Inter-BSSID Isolation Bypass Resulting in Traffic Redirection
Published 2026-03-04 · Analyzed
7.6EPSS 0.003
CVE-2026-23821
Inconsistent input filtering allows Authenticated Command Injection in AOS-10 CLI
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-23820
Inconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLI
Published 2026-05-12 · Analyzed
7.2EPSS 0.006
CVE-2026-23601
Frame Injection via Shared GTK Allows Traffic Spoofing and Client Compromise
Published 2026-03-04 · Analyzed
5.4EPSS 0.001
CVE-2026-44874
Authenticated Arbitrary File Download via AOS-10 Web-Based Management Interface
Published 2026-05-12 · Analyzed
4.9EPSS 0.005
CVE-2026-23810
Cross-BSSID GTK Re-encryption and Traffic Injection
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23811
Unauthorized Bi-Directional Traffic Interception via L2/L3 Manipulation
Published 2026-03-04 · Analyzed
4.3EPSS 0.002
CVE-2026-23812
Security Boundary Bypass via Routing Node Impersonation
Published 2026-03-04 · Analyzed
4.3EPSS 0.001