PT-2025-15461 · Aruba · Aos-8 Instant+1
Published
2025-04-08
·
Updated
2025-04-08
·
CVE-2025-27079
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
AOS-8 Instant versions prior to the fixed version
AOS-10 AP versions prior to the fixed version
Description:
A vulnerability in the file creation process on the command line interface could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating system, leading to potential system compromise.
Recommendations:
For AOS-8 Instant, update to a version that includes the fix for this issue.
For AOS-10 AP, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the command line interface until a patch is available.
Fix
LPE
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aos-10 Ap
Aos-8 Instant