{"api_version":"v1","generated_at":"2026-10-10T07:35:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-hewlett-packard-enterprise-hpe-aos-10-ap-73e6b378b377","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"AOS-10 AP","next_cursor":null,"observations":[{"affected":"10.7.0.0 \u2264 10.7.0.1; 10.4.0.0 \u2264 10.4.1.5; 8.12.0.0 \u2264 8.12.0.3; 8.10.0.0 \u2264 8.10.0.15","affected_versions_present":true,"cve_id":"CVE-2025-27079","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27079","fixed":"A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.","last_modified":"2026-02-26T18:28:38.253Z","patch_url":"https://csaf.arubanetworking.hpe.com/2025/hpe_aruba_networking_-_hpesbnw04844.json","primary_source":"","published":"2025-04-08T15:57:33.673Z"},{"affected":"10.7.0.0 \u2264 10.7.0.1; 10.4.0.0 \u2264 10.4.1.5; 8.12.0.0 \u2264 8.12.0.3; 8.10.0.0 \u2264 8.10.0.15","affected_versions_present":true,"cve_id":"CVE-2025-27078","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27078","fixed":"A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.","last_modified":"2026-02-26T18:28:38.521Z","patch_url":"https://csaf.arubanetworking.hpe.com/2025/hpe_aruba_networking_-_hpesbnw04844.json","primary_source":"","published":"2025-04-08T15:57:02.519Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"Hewlett Packard Enterprise (HPE)"}}
