---
id: CVE-2025-37146
title: >-
  A vulnerability in the web-based management interface of network access point
  configuration services could allow an authenticated remote attacker to perform
  remote command execution
summary: >-
  A vulnerability in the web-based management interface of network access point
  configuration services could allow an authenticated remote attacker to perform
  remote command execution. Successful exploitation could allow an attacker to
  exe…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-37146'
references:
  - url: >-
      https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04958en_us&docLocale=en_US
    label: security-alert@hpe.com
tags:
  - nvd
epss: 0.0089
epssPercentile: 0.58104
ingestedAt: '2026-10-08T11:31:27.397Z'
---

## Overview

A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
