CVE-2025-37141: Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37141?
The severity of CVE-2025-37141 is significant due to the potential exploitation for arbitrary file downloads by authenticated users.
How do I fix CVE-2025-37141?
To fix CVE-2025-37141, update to the latest patched version of AOS-10 GW or AOS-8 Controller/Mobility Conductor that mitigates this vulnerability.
Who is affected by CVE-2025-37141?
CVE-2025-37141 affects users of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems.
What type of attack does CVE-2025-37141 facilitate?
CVE-2025-37141 facilitates arbitrary file download attacks, potentially allowing sensitive files to be downloaded by an attacker.
Is user authentication enough to mitigate the risks of CVE-2025-37141?
User authentication alone is not enough to mitigate the risks of CVE-2025-37141, as it can still be exploited by authenticated malicious actors.