CVE-2025-37138: Authenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required)
An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37138?
CVE-2025-37138 has been classified with a high severity due to the potential for command injection exploitation.
How do I fix CVE-2025-37138?
To mitigate CVE-2025-37138, ensure that physical access to the AOS-10 GW, AOS-8 Controller, or Mobility Conductor is restricted.
What are the affected products of CVE-2025-37138?
CVE-2025-37138 affects AOS-10 GW, AOS-8 Controller, and Mobility Conductor.
Can CVE-2025-37138 be exploited remotely?
No, CVE-2025-37138 cannot be exploited remotely as it requires physical access to the affected controllers.
What does the command injection in CVE-2025-37138 allow?
The command injection vulnerability in CVE-2025-37138 could allow an attacker with physical access to execute arbitrary commands on the device.