CVE-2025-37134: Authenticated Command Injection Vulnerability in the Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37134?
CVE-2025-37134 has a high severity level due to its potential for authenticated command injection by malicious actors.
How do I fix CVE-2025-37134?
To fix CVE-2025-37134, ensure that you update to the latest version of the AOS-8 Controller/Mobility Conductor software that addresses this vulnerability.
Who is affected by CVE-2025-37134?
CVE-2025-37134 affects users of the AOS-8 Controller/Mobility Conductor operating system and related products.
What type of vulnerability is CVE-2025-37134?
CVE-2025-37134 is classified as a command injection vulnerability, allowing arbitrary command execution.
What are the potential consequences of exploiting CVE-2025-37134?
Exploiting CVE-2025-37134 could lead to unauthorized command execution as a privileged user on the system.