CVE-2026-23825: Unauthenticated Denial-of-Service via Crafted Messages in a Network Protocol Handling Component
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23825?
The severity of CVE-2026-23825 is rated as high with a score of 7.5.
How do I fix CVE-2026-23825?
To fix CVE-2026-23825, update to the latest version of ArubaOS that addresses the vulnerability.
What type of attack does CVE-2026-23825 facilitate?
CVE-2026-23825 facilitates an unauthenticated denial-of-service attack via crafted messages.
Which operating systems are affected by CVE-2026-23825?
CVE-2026-23825 affects AOS-8 and AOS-10 Operating Systems.
What is required for an attacker to exploit CVE-2026-23825?
An attacker only needs to send specially crafted network messages to exploit CVE-2026-23825 as it does not require authentication.