Arubaos (Aos)
34 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Arubaos (Aos), a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Arubaos (Aos) CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 17 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 12 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 5 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 34 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High17
- Medium17
Latest CVEs
The 15 most recently published vulnerabilities affecting Arubaos (Aos).
- CVE-2026-23823Authenticated Command Injection leads to RCE in AOS-10 CLI Command7.2
- CVE-2026-23822Unauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of Service5.3
- CVE-2026-23821Inconsistent input filtering allows Authenticated Command Injection in AOS-10 CLI7.2
- CVE-2026-23820Inconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLI7.2
- CVE-2026-23819Error in SSID Processing allows Stored XSS in Web Management Interface8.8
- CVE-2025-37179Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System5.3
- CVE-2025-37178Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System5.3
- CVE-2025-37177Authenticated Arbitrary File Deletion Vulnerability in AOS-10 or AOS-8 Command Line Interface (CLI)6.5
- CVE-2025-37176Authenticated Command Injection Vulnerability in an AOS-8 operating system's internal workflow6.5
- CVE-2025-37175Authenticated Arbitrary File Upload Vulnerability in AOS-10 or AOS-8 Web-Based Management Interface7.2
- CVE-2025-37174Authenticated Arbitrary File Write Vulnerability in AOS 10 and AOS-8 Web-Based Management Interface7.2
- CVE-2025-37173Improper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)7.2
- CVE-2025-37172Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface7.2
- CVE-2025-37171Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface7.2
- CVE-2025-37170Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface7.2
Product grouping is registry-driven, with AI assist and human review. How it works