CVE-2026-23808Disclosure(arubanetworks / 7010)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could allow a remote malicious actor to perform unauthorized frame injection, bypass client isolation, interfere with cross-client traffic, and compromise network segmentation, integrity, and confidentiality.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 7010
  • 7030
  • 7205
  • 7210

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
701070307205721072207240xm728090049004-lte9012

2 versions affected across 18 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-04: 1Mentions · 2026-03-10: 103-0403-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 HPE Aruba Networking AOS, GTK Installation Flaw, #CVE-2026-23808 (MEDIUM) https://dailycve.com/hpe-aruba-networking-aos-gtk-installation-flaw-cve-2026-23808-medium/

    Post summary

    The tweet announces a medium‑severity CVE in HPE Aruba Networking AOS by linking to a dailycve article, but does not provide PoC, exploit, patch, or technical details.

    0000038
    166 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23808 A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal K… https://www.cve.org/CVERecord?id=CVE-2026-23808

    Post summary

    A new vulnerability (CVE-2026-23808) has been identified in a wireless roaming protocol that could allow an attacker to install a malicious component, but no further technical, exploit, or mitigation details are disclosed.

    00000153
    56.6K followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
HWarubanetworks7010---
HWarubanetworks7030---
HWarubanetworks7205---
HWarubanetworks7210---
HWarubanetworks7220---
HWarubanetworks7240xm---
HWarubanetworks7280---
HWarubanetworks9004---
HWarubanetworks9004-lte---
HWarubanetworks9012---
HWarubanetworks9106---
HWarubanetworks9114---
HWarubanetworks9240---
HWarubanetworksap-634---
HWarubanetworksap-635---
HWarubanetworksap-654---
HWarubanetworksap-655---
OSarubanetworksarubaos---
OSarubanetworksarubaos10.8.0.0--

Explore more