CVE-2025-37135: Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conductor Command Line Interface (CLI)
Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37135?
CVE-2025-37135 is considered a high severity vulnerability due to the potential for arbitrary file deletion by unauthorized actors.
How do I fix CVE-2025-37135?
To fix CVE-2025-37135, ensure that your AOS-8 Controller/Mobility Conductor is updated to the latest patched version provided by the vendor.
Who is affected by CVE-2025-37135?
CVE-2025-37135 affects the AOS-8 Controller and Mobility Conductor in environments where file management is exposed to authenticated users.
What are the risks associated with CVE-2025-37135?
The risks associated with CVE-2025-37135 include the potential for data loss and disruption to system operations due to unauthorized file deletions.
Are there any mitigations for CVE-2025-37135?
Mitigations for CVE-2025-37135 include implementing stricter access controls and continuously monitoring user activities within the AOS-8 environment.