CVE-2025-37143: Authenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web Interface (Physical Access Required)
An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download arbitrary files through carefully constructed exploits.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37143?
CVE-2025-37143 is considered a high severity vulnerability due to its potential for arbitrary file download by authenticated attackers.
How do I fix CVE-2025-37143?
To mitigate CVE-2025-37143, update to the latest patched version of the AOS-10 GW or AOS-8 Controller/Mobility Conductor software.
Who is affected by CVE-2025-37143?
CVE-2025-37143 affects users of AOS-10 GW, AOS-8 Controller, and Mobility Conductor operating systems.
What type of vulnerability is CVE-2025-37143?
CVE-2025-37143 is an arbitrary file download vulnerability found in the web-based management interface.
Can CVE-2025-37143 be exploited remotely?
CVE-2025-37143 requires authentication, but can lead to remote exploitation allowing downloading of arbitrary files.