CVE-2018-7082: Arubanetworks Aruba Instant

High severity, CVSS 7.2. EPSS: 4.3% chance of exploitation in the next 30 days.

A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration in a way that would not be logged. Workaround: None. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0

Affected products

  • Arubanetworks Aruba Instant: from 4.0, before 4.2.4.12 (fixed in 4.2.4.12); from 6.5.0, before 6.5.4.11 (fixed in 6.5.4.11); from 8.3.0.0, before 8.3.0.6 (fixed in 8.3.0.6); from 8.4.0, before 8.4.0.1 (fixed in 8.4.0.1)
  • Siemens Scalance w1750d Firmware: before 8.4.0.1 (fixed in 8.4.0.1)

Published 2019-05-10. Last modified 2026-06-17.