CVE-2026-44866: Authenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What are the known vulnerabilities associated with CVE-2026-44866?
CVE-2026-44866 describes command injection vulnerabilities in the web-based management interface of AOS-8 and AOS-10 systems.
What is the impact of CVE-2026-44866 on affected systems?
Successful exploitation of CVE-2026-44866 could allow an authenticated attacker to execute arbitrary commands on the affected operating systems.
How do I mitigate CVE-2026-44866?
To mitigate CVE-2026-44866, upgrade to the latest patched versions of AOS-8 or AOS-10 as recommended by the vendor.
Which software versions are impacted by CVE-2026-44866?
CVE-2026-44866 affects AOS versions 8 and 10, specifically those within certain vulnerable ranges as identified by the vendor.
Is authentication required to exploit CVE-2026-44866?
Yes, exploitation of CVE-2026-44866 requires authenticated access to the web-based management interface.