SecAlerts
AOS logo

AOS

Security Risk Profile

48
/100
medium

Security Risk Score

Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from January 14, 2025 to present

22
Total CVEs
7
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
6.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
48/100
medium

Severity Distribution

Critical
0
High
7
Medium
15
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Command Injection
5
2
OS Command Injection
5
3
Code Injection
2
4
Path Traversal
2
5
Malicious File Upload
1

Most Affected Products

1. Arubanetworks Arubaos70
2. HPE Arubaos-cx10
3. AOS AOS-10 GW10
4. AOS AOS-8 Controller/Mobility Conductor7
5. AOS AOS-8 Controller6

Recent Vulnerabilities

See more →
CVE-2025-37179
CVSS 5.3medium

Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System

1/13/2026🔧 No Patch
CVE-2025-37178
CVSS 7.5high

Out-of-Bounds Read Vulnerabilities Leading to Process Crash in AOS-8 Operating System

1/13/2026🔧 No Patch
CVE-2025-37171
CVSS 7.2high

Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface

1/13/2026🔧 No Patch
CVE-2025-37158
CVSS 8.8high

Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX

11/18/2025🔧 No Patch
CVE-2025-37157
CVSS 8.8high

Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX

11/18/2025🔧 No Patch
CVE-2025-37145
CVSS 4.9medium

Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface

10/14/2025🔧 No Patch
CVE-2025-37144
CVSS 4.9medium

Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface

10/14/2025🔧 No Patch
CVE-2025-37143
CVSS 4.9medium

Authenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web Interface (Physical Access Required)

10/14/2025🔧 No Patch
CVE-2025-37142
CVSS 4.9medium

Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface

10/14/2025🔧 No Patch
CVE-2025-37141
CVSS 4.9medium

Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface

10/14/2025🔧 No Patch

Monitor AOS in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

AOS Security Vulnerabilities & Risk Score | 22 CVEs | SecAlerts - SecAlerts