CVE-2025-37162: Authenticated Command Injection Vulnerability Leading to Arbitrary Remote Command Execution
Published Nov 18, 2025
·Updated
A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduct a command injection attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Affected Software
1 affected component
Arubanetworks Arubaos<10.7.2.0
Event History
Nov 18, 2025
CVE Published
via MITRE·07:23 PM
Data Sourced
via MITRE·07:23 PM
DescriptionSeverity
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37162?
CVE-2025-37162 is classified as a critical vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2025-37162?
To fix CVE-2025-37162, upgrade to a patched version of ArubaOS above 10.7.2.0.
3
Who is affected by CVE-2025-37162?
CVE-2025-37162 affects devices running ArubaOS versions up to 10.7.2.0.
4
What types of attacks can CVE-2025-37162 enable?
CVE-2025-37162 can enable authenticated remote command injection attacks.
5
What should I do if I have detected CVE-2025-37162 on my system?
If CVE-2025-37162 is detected, immediately apply security patches and assess for possible exploitations.