CVE-2025-23051: Authenticated Remote Code Execution in AOS Web-based Management Interface
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23051?
CVE-2025-23051 is considered a critical severity vulnerability due to its potential to allow authenticated users to overwrite arbitrary system files.
How do I fix CVE-2025-23051?
To fix CVE-2025-23051, apply the latest security patches provided by the vendor AOS for AOS-8 and AOS-10 operating systems.
Who is affected by CVE-2025-23051?
CVE-2025-23051 affects users and administrators of the AOS-8 and AOS-10 operating systems with authenticated access to the web-based management interface.
What types of attacks can leverage CVE-2025-23051?
Exploitation of CVE-2025-23051 can allow attackers to conduct parameter injection attacks, potentially leading to critical system file modifications.
Is CVE-2025-23051 currently being exploited in the wild?
As of now, there have been no confirmed reports of CVE-2025-23051 being actively exploited in the wild, but immediate remediation is recommended.