CVE-2025-27083: Authenticated Command Injection Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27083?
CVE-2025-27083 is considered a critical vulnerability due to the potential for authenticated command injection.
How do I fix CVE-2025-27083?
To fix CVE-2025-27083, apply the latest security patches provided by Aruba Networks for AOS-10 and AOS-8 Controller/Mobility Conductor.
What are the potential impacts of CVE-2025-27083?
The potential impacts of CVE-2025-27083 include unauthorized command execution and complete system compromise by an authenticated attacker.
Who is affected by CVE-2025-27083?
CVE-2025-27083 affects users of Aruba Networks AOS-10 and AOS-8 Controller/Mobility Conductor systems.
Is authentication required to exploit CVE-2025-27083?
Yes, exploitation of CVE-2025-27083 requires the attacker to have authenticated access to the vulnerable web-based management interface.