CVE 4.9 MEDIUM

Authenticated Arbitrary File Download via AOS-10 Web-Based Management Interface_CVE-2026-44874

4.9 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Description

A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of confidential system information, potentially enabling further attacks against the affected device.

Basic Information

ID CVE-2026-44874
Source hpe
Published May 12, 2026 at 19:19
Modified May 12, 2026 at 19:49

Affected Product

Vendor Hewlett Packard Enterprise (HPE)
Product HPE Aruba Networking Wireless Operating System (AOS)
Version 10.7.0.0
Affected Versions Hewlett Packard Enterprise (HPE) HPE Aruba Networking Wireless Operating System (AOS) 10.7.0.0
Hewlett Packard Enterprise (HPE) HPE Aruba Networking Wireless Operating System (AOS) 10.8.0.0
Hewlett Packard Enterprise (HPE) HPE Aruba Networking Wireless Operating System (AOS) 10.4.0.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.