VYPR

AOS-8 Controller/Mobility Conductor

by Arubanetworks

CVEs (4)

  • CVE-2025-27083HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on…

  • CVE-2025-27082HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.00

    Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary…

  • CVE-2025-27084MedApr 8, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the…

  • CVE-2025-37135Oct 14, 2025
    risk 0.00cvss epss 0.00

    Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the…