CVE-2025-37139: Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable Boot
Published Oct 14, 2025
·Updated
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.
Affected Software
1 affected component
Aruba Networks ArubaOS
Event History
Oct 14, 2025
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness