← Back to CVE List
CVE-2025-37174NVD
Vulnerability Summary
Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.
CVSS v3.1 Base Metrics — Score 7.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Arubanetworks Arubaos >= 6.5.4.0 and < 8.10.0.21
- Arubanetworks Arubaos >= 8.11.0.0 and < 8.13.1.1
- Arubanetworks Arubaos >= 10.3.0.0 and < 10.4.1.10
- Arubanetworks Arubaos >= 10.5.0.0 and < 10.7.2.2
- Arubanetworks Arubaos 8.10.0.21
- Arubanetworks Arubaos 8.13.1.1
- Arubanetworks Arubaos 10.4.1.10
- Arubanetworks Arubaos 10.7.2.2