SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-44852

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface.

HIGH 7.2EPSS 0.44%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system as a privileged user.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.44% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-296
Affected
arubanetworks/arubaos · arubanetworks/sd-wan
Source
security-alert@hpe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.