CVE-2025-27082: Authenticated Remote Code Execution Vulnerabilities in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File Write
Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27082?
CVE-2025-27082 has a high severity rating due to the potential for arbitrary file write vulnerabilities.
How do I fix CVE-2025-27082?
To mitigate CVE-2025-27082, update to the latest version of Arista Networks AOS-10 GW or AOS-8 Controller/Mobility Conductor that addresses this vulnerability.
What systems are affected by CVE-2025-27082?
CVE-2025-27082 affects Arista Networks AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems.
Can an unauthenticated attacker exploit CVE-2025-27082?
No, only authenticated attackers can exploit CVE-2025-27082 to gain arbitrary file upload capabilities.
What are the potential risks associated with CVE-2025-27082?
The exploitation of CVE-2025-27082 can lead to unauthorized file uploads and the execution of arbitrary commands on vulnerable systems.