Remote Code Execution Vulnerability in AOS-8 Instant and AOS-10 Access Points by HPE
CVE-2025-27079
6MEDIUM
Key Information:
- Vendor
- HP (HP)
- Status
- Aos-10 Ap
- Vendor
- CVE Published:
- 8 April 2025
Summary
A security flaw in the file creation process within the command line interface of the AOS-8 Instant and AOS-10 Access Points allows authenticated remote attackers to execute arbitrary commands on the underlying operating system. Exploiting this vulnerability could lead to a compromised system, emphasizing the importance of implementing security measures and updates to mitigate associated risks.
Affected Version(s)
AOS-10 AP 10.7.0.0 <= 10.7.0.1
AOS-10 AP 10.7.0.0 <= 10.7.0.1
AOS-10 AP 10.4.0.0 <= 10.4.1.5
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ZZ from Moonlight Bug Hunter