Arbitrary File Deletion Vulnerability in AOS-8 Controller by HPE
CVE-2025-37136
6.5MEDIUM
What is CVE-2025-37136?
An arbitrary file deletion vulnerability exists in the command-line interface of HPE's AOS-8 Controller and Mobility Conductor. This issue allows an authenticated remote malicious actor to exploit the vulnerability, providing them the potential to delete arbitrary files from the affected system. The exploitation can lead to significant data loss and disruption of service, emphasizing the need for immediate attention and remediation strategies for users.
Affected Version(s)
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.4.0.0 <= 10.4.1.8