CVE-2025-23052: Hewlett Packard Enterprise HPE HPE Aruba Networking Aos

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

Affected products

  • Hewlett Packard Enterprise HPE HPE Aruba Networking Aos: from 10.4.0.0, up to and including 10.4.1.4; from 8.12.0.0, up to and including 8.12.0.2; from 8.10.0.0, up to and including 8.10.0.14

Published 2025-01-14. Last modified 2026-06-17.