Skip to content
VulniPulse

HPE Aruba Networking AOS-8 Mobility Controllers Vulnerabilities & Security Advisories

18 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as AOS-8 Mobility Controllers, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 10 high, 8 medium.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba AOS-8 Mobility Controllers advisories

High7.5Aruba Updated

High [CVE-2026-23825] AOS-10: Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial-of-service condition.

CVE-2026-23825
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2025-37175] Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or…

Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.

CVE-2025-37175
Wireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37174] AOS-10: Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running…

Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37174
Wireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37173] AOS-10: improper input handling vulnerability exists in the web-based management interface of mobility conductors running either…

An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system.

CVE-2025-37173
Wireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37172] Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8…

Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37172
Wireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High8.2Aruba

High [CVE-2025-37168] Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating…

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in denial-of-service conditions on affected devices.

CVE-2025-37168
Wireless & ControllersMobility ConductorArubaOS
Jan 13, 2026
High7.2Aruba

High [CVE-2025-37134] authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating…

An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37134
Wireless & ControllersMobility ConductorArubaOS
Oct 14, 2025
High7.2Aruba

High [CVE-2025-37132] arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8…

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.

CVE-2025-37132
Wireless & ControllersMobility ConductorArubaOS
Oct 14, 2025
High7.2Aruba

High [CVE-2025-27083] Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based…

Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-27083
Wireless & ControllersMobility ConductorArubaOS
Apr 8, 2025
High7.2Aruba

High [CVE-2025-27082] Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8…

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.

CVE-2025-27082
Wireless & ControllersMobility ConductorArubaOS
Apr 8, 2025

← All Aruba advisories