f.zz.de
posts /

ArubaOS AP Firmware

Posted Fri 07 Oct 2022 09:32:15 AM CEST Florian Lohoff
in

Aruba published a set of CVEs concerning the AP Firmware, but the issue is that when you dont have a login, and your APs dont have direct internet access or the internet access is crippled you are dead in the water.

But when looking at some debug output you'll find the original URLs the APs would try to download the firmware:

Like this. The last part of the URI can be determined from the Aruba Website and is platform and version dependent:

http://common.cloud.hpe.com/ccssvc/ccs-system-firmware-registry/IAP/ArubaInstant_Gemini_8.11.0.0_85179