CVE-2025-37173: Improper Input Handling Vulnerability in Authenticated Configuration API Endpoint (AOS-10/AOS-8 Web UI)
An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended behavior on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37173?
CVE-2025-37173 has a critical severity rating due to the potential for authenticated exploitation.
How do I fix CVE-2025-37173?
To fix CVE-2025-37173, ensure that your Mobility Conductor is updated to the latest version provided by the vendor.
What systems are affected by CVE-2025-37173?
CVE-2025-37173 affects Mobility Conductor systems running AOS-10 and AOS-8 operating systems.
What type of vulnerability is CVE-2025-37173?
CVE-2025-37173 is categorized as an improper input handling vulnerability in the web-based management interface.
What could happen if CVE-2025-37173 is exploited?
If exploited, CVE-2025-37173 could allow an attacker to compromise the management capabilities of the affected system.