CVE-2025-27082

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
08/04/2025
Last modified:
12/11/2025

Description

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 8.10.0.0 (including) 8.10.0.16 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 8.12.0.0 (including) 8.12.0.4 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 10.4.0.0 (including) 10.4.1.7 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 10.7.0.0 (including) 10.7.1.1 (excluding)