CVE Tools

Arubaos (Aos)

34 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Arubaos (Aos), a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

Arubaos (Aos) CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Arubaos (Aos) CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-1017
2025-110
2025-120
2026-0112
2026-020
2026-030
2026-040
2026-055
2026-060
2026-070
2026-080
2026-090

Severity

How the 34 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High1750%
  • Medium1750%

Latest CVEs

The 15 most recently published vulnerabilities affecting Arubaos (Aos).

  1. CVE-2026-23823Authenticated Command Injection leads to RCE in AOS-10 CLI Command7.2
  2. CVE-2026-23822Unauthenticated XML External Entity Injection in AOS-8 Instant allows Denial of Service5.3
  3. CVE-2026-23821Inconsistent input filtering allows Authenticated Command Injection in AOS-10 CLI7.2
  4. CVE-2026-23820Inconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLI7.2
  5. CVE-2026-23819Error in SSID Processing allows Stored XSS in Web Management Interface8.8
  6. CVE-2025-37179Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System5.3
  7. CVE-2025-37178Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System5.3
  8. CVE-2025-37177Authenticated Arbitrary File Deletion Vulnerability in AOS-10 or AOS-8 Command Line Interface (CLI)6.5
  9. CVE-2025-37176Authenticated Command Injection Vulnerability in an AOS-8 operating system's internal workflow6.5
  10. CVE-2025-37175Authenticated Arbitrary File Upload Vulnerability in AOS-10 or AOS-8 Web-Based Management Interface7.2
  11. CVE-2025-37174Authenticated Arbitrary File Write Vulnerability in AOS 10 and AOS-8 Web-Based Management Interface7.2
  12. CVE-2025-37173Improper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)7.2
  13. CVE-2025-37172Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface7.2
  14. CVE-2025-37171Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface7.2
  15. CVE-2025-37170Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store