CVE-2025-37138Medium· 6.2▾ SunlitAn authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardw…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system.
arubaos >= 8.10.0.0, < 8.10.0.19arubaos >= 8.12.0.0, < 8.12.0.6arubaos >= 8.13.0.0, < 8.13.1.0arubaos >= 10.4.0.0, < 10.4.1.9arubaos >= 10.7.0.0, < 10.7.2.1Upgrade past the affected range:
arubaos 10.7.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-76675Critical· 9.1A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways
CVE-2026-76698Medium· 6.5A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways
CVE-2025-11523Medium· 6.3A vulnerability was detected in Tenda AC7 15.03.06.44
CVE-2025-59834Critical· 9.8ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0