CVE-2025-37172: Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37172?
CVE-2025-37172 is classified as a high severity vulnerability due to its potential for authenticated command injection.
How do I fix CVE-2025-37172?
To fix CVE-2025-37172, update your Aruba Networks AOS-8 software to the latest patched version.
Who is affected by CVE-2025-37172?
CVE-2025-37172 affects all deployments of the Aruba Networks AOS-8 operating system running mobility conductors.
What are the risks of CVE-2025-37172?
Exploitation of CVE-2025-37172 could allow an authenticated attacker to execute arbitrary commands on the affected system.
When was CVE-2025-37172 disclosed?
CVE-2025-37172 was disclosed in 2025 and should be remediated as soon as possible to protect network security.