Authenticated Command Injection Vulnerability in HPE Network Management Service
CVE-2025-23052
What is CVE-2025-23052?
An authenticated command injection vulnerability exists within the command line interface of HPE's network management service. When exploited, this flaw could enable an attacker to run arbitrary commands in the context of a privileged user on the host operating system. This risk emphasizes the importance of securing command interfaces and implementing robust authentication measures to prevent unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HPE Aruba Networking AOS 10.4.0.0 <= 10.4.1.4
HPE Aruba Networking AOS 8.12.0.0 <= 8.12.0.2
HPE Aruba Networking AOS 8.10.0.0 <= 8.10.0.14
News Articles
References
CVSS V3.1
Timeline
- đź“°
First article discovered by GBHackers News
Vulnerability published
