CVE-2025-37157: Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37157?
CVE-2025-37157 is considered a critical severity vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2025-37157?
To fix CVE-2025-37157, update the AOS-CX Operating System to the latest version provided by AOS.
Who is affected by CVE-2025-37157?
CVE-2025-37157 affects users of the AOS-CX Operating System who have not applied the recommended security updates.
What type of attack can CVE-2025-37157 facilitate?
CVE-2025-37157 can facilitate command injection, allowing an authenticated remote attacker to execute arbitrary code.
Is authentication required for exploiting CVE-2025-37157?
Yes, CVE-2025-37157 requires an authenticated user to exploit the vulnerability and conduct Remote Code Execution.