Remote Code Execution Vulnerability in AOS-8 Instant and AOS-10 Access Points by HPE
CVE-2025-27079

6MEDIUM

Key Information:

Vendor
HP (HP)
Status
Aos-10 Ap
Vendor
CVE Published:
8 April 2025

Summary

A security flaw in the file creation process within the command line interface of the AOS-8 Instant and AOS-10 Access Points allows authenticated remote attackers to execute arbitrary commands on the underlying operating system. Exploiting this vulnerability could lead to a compromised system, emphasizing the importance of implementing security measures and updates to mitigate associated risks.

Affected Version(s)

AOS-10 AP 10.7.0.0 <= 10.7.0.1

AOS-10 AP 10.7.0.0 <= 10.7.0.1

AOS-10 AP 10.4.0.0 <= 10.4.1.5

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZZ from Moonlight Bug Hunter
.