Arbitrary File Download Vulnerability in AOS-10 GW and AOS-8 Controller by HPE
CVE-2025-37142
4.9MEDIUM
What is CVE-2025-37142?
A security flaw in the CLI binary of HPE's AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems allows authenticated attackers to craft specific exploits leading to arbitrary file downloads. This vulnerability poses a risk of unauthorized access to sensitive files, potentially compromising system integrity and confidentiality. Organizations must address this vulnerability to safeguard their networks.
Affected Version(s)
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.7.0.0 <= 10.7.1.1
ArubaOS (AOS) 10.4.0.0 <= 10.4.1.8
