CVE-2025-37174: Authenticated Arbitrary File Write Vulnerability in AOS 10 and AOS-8 Web-Based Management Interface
Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37174?
CVE-2025-37174 is classified as a high-severity vulnerability due to its potential for unauthorized file manipulation.
How do I fix CVE-2025-37174?
To fix CVE-2025-37174, update your Aruba Networks AOS to the latest available version that addresses this vulnerability.
Who is affected by CVE-2025-37174?
CVE-2025-37174 affects systems running either AOS-10 or AOS-8 from Aruba Networks.
What type of vulnerability is CVE-2025-37174?
CVE-2025-37174 is an authenticated arbitrary file write vulnerability.
What could be the impact of exploiting CVE-2025-37174?
Exploiting CVE-2025-37174 could allow an attacker to write arbitrary files on the server, potentially compromising the system.