CVE Tools

Airwave

40 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Airwave, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Airwave CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Airwave CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 40 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical25%
  • High2563%
  • Medium1333%

Latest CVEs

The 15 most recently published vulnerabilities affecting Airwave.

  1. CVE-2025-37163Authenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLI7.2
  2. CVE-2023-4896Authenticated Disclosure of Sensitive Information in AirWave Management Platform6.8
  3. CVE-2015-2202Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.7.2
  4. CVE-2015-2201Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.7.2
  5. CVE-2015-1391Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.8.8
  6. CVE-2015-1390Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.6.1
  7. CVE-2022-37918Broken Access Control for some Web-based Management URLs in AirWave Management Platform8.1
  8. CVE-2022-37916Broken Access Control for some Web-based Management URLs in AirWave Management Platform8.1
  9. CVE-2022-37917Broken Access Control for some Web-based Management URLs in AirWave Management Platform8.1
  10. CVE-2021-37715A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.13.0. Aruba has released upgrades for the Aruba AirWave Management Pla...4.8
  11. CVE-2021-29137A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this...6.1
  12. CVE-2021-25167A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.8
  13. CVE-2021-25166A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.8
  14. CVE-2021-25163A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.1
  15. CVE-2021-25165A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address ...8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store