CVE-2026-44854: Authenticated Remote Code Execution via Arbitrary File Write in AOS-8 and AOS-10 Web-Based Management Interface
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44854?
CVE-2026-44854 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-44854?
To mitigate CVE-2026-44854, upgrade the affected AOS-8 or AOS-10 systems to the latest version available that addresses the vulnerability.
What systems are affected by CVE-2026-44854?
CVE-2026-44854 affects AOS-8 and AOS-10 Operating Systems, specifically within their web-based management interfaces.
Can CVE-2026-44854 be exploited remotely?
Yes, CVE-2026-44854 allows an authenticated remote attacker to execute arbitrary commands through the vulnerable web interface.
What types of attacks are possible due to CVE-2026-44854?
CVE-2026-44854 enables attackers to write arbitrary files, leading to potential remote code execution on the target system.