CVE-2025-37134High· 7.2▾ TwilightAn authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
arubaos >= 8.10.0.0, < 8.10.0.19arubaos >= 8.12.0.0, < 8.12.0.6arubaos >= 8.13.0.0, < 8.13.1.0arubaos >= 10.4.0.0, < 10.4.1.9arubaos >= 10.7.0.0, < 10.7.2.1Upgrade past the affected range:
arubaos 10.7.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-37133High· 7.2An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system
CVE-2025-37138Medium· 6.2An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system
CVE-2025-37145Medium· 4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37142Medium· 4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37143Medium· 4.9An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37144Medium· 4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems