Arbitrary File Deletion Vulnerabilities in AOS-8 Controller by HPE
CVE-2025-37135
6.5MEDIUM
What is CVE-2025-37135?
Arbitrary file deletion vulnerabilities have been uncovered in the command-line interface of the AOS-8 Controller and Mobility Conductor from Hewlett Packard Enterprise. If exploited, these vulnerabilities could enable an authenticated remote attacker to delete files at will within the affected system, potentially leading to data loss and operational disruption.
Affected Version(s)
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.4.0.0 <= 10.4.1.8