CVE-2025-37136Medium· 6.5▾ SunlitArbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
arubaos >= 8.10.0.0, < 8.10.0.19arubaos >= 8.12.0.0, < 8.12.0.6arubaos >= 8.13.0.0, < 8.13.1.0arubaos >= 10.4.0.0, < 10.4.1.9arubaos >= 10.7.0.0, < 10.7.2.1Upgrade past the affected range:
arubaos 10.7.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-37142Medium· 4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37143Medium· 4.9An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37140Medium· 4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37141Medium· 4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37135Medium· 6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor
CVE-2025-37137Medium· 6.5Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor