CVE-2025-37144: Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Affecting AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface
Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37144?
CVE-2025-37144 has been rated with a high severity due to the potential for unauthorized arbitrary file downloads.
How do I fix CVE-2025-37144?
To fix CVE-2025-37144, update to the latest patched version of AOS-10 GW, AOS-8 Controller, or Mobility Conductor.
Who is affected by CVE-2025-37144?
CVE-2025-37144 affects users of AOS-10 GW, AOS-8 Controller, and Mobility Conductor operating systems.
What can an attacker do with CVE-2025-37144?
An attacker can exploit CVE-2025-37144 to download arbitrary files from the system if they are authenticated.
Is authentication required to exploit CVE-2025-37144?
Yes, exploitation of CVE-2025-37144 requires that the attacker is authenticated on the affected systems.