CVE-2025-37158: Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX
Published Nov 18, 2025
·Updated
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
Affected Software
6 affected components
AOS AOS-CX Operating System
HPE Arubaos-cx>=10.10.0000<10.10.1170
HPE Arubaos-cx>=10.13.0000<10.13.1101
HPE Arubaos-cx>=10.14.0000<10.14.1060
HPE Arubaos-cx>=10.15.0000<10.15.1030
HPE Arubaos-cx>=10.16.0000<10.16.1001
Event History
Nov 18, 2025
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
DescriptionSeverity
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 9, 57896
Event
via NVD·11:34 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-37158?
CVE-2025-37158 is considered a critical vulnerability due to its potential for Remote Code Execution.
2
How do I fix CVE-2025-37158?
To mitigate CVE-2025-37158, apply the latest security patches provided by AOS for the AOS-CX Operating System.
3
Who is affected by CVE-2025-37158?
CVE-2025-37158 affects systems running the AOS-CX Operating System.
4
What kind of attacks are possible with CVE-2025-37158?
Exploitation of CVE-2025-37158 could allow an authenticated remote attacker to execute arbitrary commands on the affected system.
5
Is there a workaround for CVE-2025-37158?
Currently, the recommended action is to update to a secure version, as there are no known effective workarounds for CVE-2025-37158.