PT-2025-1018 · Hewlett Packard · Hpe Aruba Networking 501 Wireless Client Bridge

Nicholas Starke

·

Published

2025-01-07

·

Updated

2025-01-13

·

CVE-2024-54007

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HPE Aruba Networking 501 Wireless Client Bridge (affected versions not specified)
Description The issue is related to command injection vulnerabilities in the web interface of the HPE Aruba Networking 501 Wireless Client Bridge. These vulnerabilities could allow a remote attacker to execute arbitrary commands as a privileged user on the underlying operating system. The exploitation requires administrative authentication credentials on the host system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00215
CVE-2024-54007

Affected Products

Hpe Aruba Networking 501 Wireless Client Bridge