← Back to CVE List
CVE-2025-37170NVD
Vulnerability Summary
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Arubanetworks Arubaos >= 8.6.0.0 and < 8.10.0.21
- Arubanetworks Arubaos >= 8.11.0.0 and < 8.13.1.1
- Arubanetworks Arubaos 8.10.0.21
- Arubanetworks Arubaos 8.13.1.1