CVE 6.7 MEDIUM

Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX_CVE-2025-37157

6.7 / 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

Basic Information

ID CVE-2025-37157
Source hpe
Published Nov 18, 2025 at 18:48

Affected Product

Vendor Hewlett Packard Enterprise (HPE)
Product HPE Aruba Networkign AOS-CX
Version 10.16.0000
Affected Versions Hewlett Packard Enterprise (HPE) HPE Aruba Networkign AOS-CX 10.16.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networkign AOS-CX 10.15.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networkign AOS-CX 10.14.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networkign AOS-CX 10.13.0000
Hewlett Packard Enterprise (HPE) HPE Aruba Networkign AOS-CX 10.10.0000

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.