CVE-2025-23051: Hewlett Packard Enterprise HPE HPE Aruba Networking Aos
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
Affected products
- Hewlett Packard Enterprise HPE HPE Aruba Networking Aos: from 10.4.0.0, up to and including 10.4.1.4; from 8.12.0.0, up to and including 8.12.0.2; from 8.10.0.0, up to and including 8.10.0.14
Published 2025-01-14. Last modified 2026-06-17.