Wireless Network Traffic Redirection Vulnerability in HPE Products
CVE-2026-23809
What is CVE-2026-23809?
A vulnerability exists in HPE Wireless Solutions due to the misuse of a port-stealing method that has been adapted for Wi-Fi networks utilizing multiple BSSIDs. This flaw allows attackers to exploit the relationship between BSSIDs and their corresponding virtual ports, potentially bypassing inter-BSSID isolation safeguards. The exploitation of this vulnerability could permit an attacker to intercept and redirect network traffic, leading to risks such as eavesdropping, session hijacking, or denial of service, compromising security and privacy in network communications.
Affected Version(s)
HPE Aruba Networking Wireless Operating System (AOS-10 & AOS-8) 10.8.0.0
HPE Aruba Networking Wireless Operating System (AOS-10 & AOS-8) 10.8.0.0
HPE Aruba Networking Wireless Operating System (AOS-10 & AOS-8) 10.7.0.0 <= 10.7.2.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
