logo

JoCERT Warns Of HPE Aruba Command Injection Flaws

ID: 83a257fc-7c12-5221-a5d7-e84ed60e8e02

STIX ID: report--83a257fc-7c12-5221-a5d7-e84ed60e8e02

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2025-10-17

Date Updated: 2026-07-16

...
...

This advisory reports two high-severity command injection vulnerabilities (CVE-2024-54006 and CVE-2024-54007) in HPE Aruba 501 Wireless Client Bridge firmware (≤ V2.1.1.0-B0030) that allow authenticated administrators to execute arbitrary commands; both are CVSS 7.2 and a public PoC exists — HPE recommends upgrading to V2.1.2.0-B0033 or later, restricting management access, auditing devices, and monitoring for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.