CVE-2025-37140: Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37140?
CVE-2025-37140 has been classified as a high severity vulnerability due to its potential to allow authenticated attackers to exploit arbitrary file downloads.
How do I fix CVE-2025-37140?
To mitigate CVE-2025-37140, it is recommended to apply the latest patches provided by AOS for affected software versions.
Which versions of AOS are affected by CVE-2025-37140?
CVE-2025-37140 affects AOS-10 GW, AOS-8 Controller, and AOS Mobility Conductor.
What types of attacks can exploit CVE-2025-37140?
CVE-2025-37140 can be exploited through carefully crafted requests by authenticated attackers to download arbitrary files.
Who is responsible for patching CVE-2025-37140?
It is the responsibility of system administrators using affected AOS products to ensure they apply necessary patches for CVE-2025-37140.