CVE-2018-16417: Arubanetworks Instant

High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.

Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.

Affected products

  • Arubanetworks Instant: from 4.0.0.0, before 4.2.4.12 (fixed in 4.2.4.12); from 6.5.0.0, before 6.5.4.11 (fixed in 6.5.4.11); from 8.3.0.0, before 8.3.0.6 (fixed in 8.3.0.6); from 8.4.0.0, before 8.4.0.1 (fixed in 8.4.0.1)
  • Siemens w1750d Firmware: before 8.4.0.1 (fixed in 8.4.0.1)

Published 2019-10-30. Last modified 2026-06-17.