Authenticated Command Injection Vulnerability in HPE Mobility Conductors
CVE-2025-37171
7.2HIGH
What is CVE-2025-37171?
A critical security flaw has been identified in the web-based management interface of HPE Mobility Conductors running the AOS-8 operating system. This vulnerability allows authenticated users to execute arbitrary commands at the privileged user level on the underlying operating system. Successfully exploiting this flaw can pose significant risks, as it may grant malicious actors extensive control over affected systems, leading to potential data breaches and operational disruptions. Organizations must promptly assess and remediate this issue to safeguard their environments.
Affected Version(s)
ArubaOS (AOS) 8.12.0.0 <= 8.13.1.0
ArubaOS (AOS) 8.12.0.0 <= 8.13.1.0
ArubaOS (AOS) 8.10.0.0 <= 8.10.0.20
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
zzcentury from Ubisectech Sirius Team
