There is a command injection vulnerability that could...
Critical severity
Unreviewed
Published
Dec 12, 2022
to the GitHub Advisory Database
•
Updated May 2, 2025
Description
Published by the National Vulnerability Database
Dec 12, 2022
Published to the GitHub Advisory Database
Dec 12, 2022
Last updated
May 2, 2025
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
References