CVE-2026-44865: Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44865?
CVE-2026-44865 is classified as a high severity vulnerability due to the potential for authenticated command injection.
How do I fix CVE-2026-44865?
To resolve CVE-2026-44865, upgrade your AOS-8 or AOS-10 systems to the latest patched versions provided by the vendor.
What are the affected versions for CVE-2026-44865?
CVE-2026-44865 affects AOS versions 8 and 10, specifically within certain specified version ranges.
What types of attacks can CVE-2026-44865 enable?
Successful exploitation of CVE-2026-44865 could allow an authenticated attacker to execute arbitrary commands on the system.
Is CVE-2026-44865 present in unpatched systems?
Yes, unpatched systems running AOS-8 or AOS-10 within the affected version ranges are vulnerable to CVE-2026-44865.