CVE-2025-37162Medium· 6.5▾ SunlitA vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the un…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
arubaos >= 10.7.1.0, < 10.7.2.0Upgrade past the affected range:
arubaos 10.7.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-37161High· 7.5A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service
CVE-2025-37133High· 7.2An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system
CVE-2025-37134High· 7.2An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system
CVE-2025-37138Medium· 6.2An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system
CVE-2025-37145Medium· 4.9Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems
CVE-2025-37142Medium· 4.9Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems