CVE-2025-37175: Authenticated Arbitrary File Upload Vulnerability in AOS-10 or AOS-8 Web-Based Management Interface
Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and execute arbitrary commands on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37175?
CVE-2025-37175 is classified as a high-severity vulnerability due to the potential for authenticated arbitrary file uploads.
How do I fix CVE-2025-37175?
To mitigate CVE-2025-37175, update your Mobility Conductors to a version above AOS-10 and AOS-8 that addresses this vulnerability.
What are the affected systems for CVE-2025-37175?
CVE-2025-37175 affects Mobility Conductors running AOS-10 or AOS-8 operating systems through their web-based management interface.
What type of attacks can CVE-2025-37175 facilitate?
CVE-2025-37175 can facilitate attacks that allow an authenticated user to upload arbitrary files, potentially leading to further exploitation.
Is there a known exploit for CVE-2025-37175?
As of now, there are no publicly disclosed exploit details specifically associated with CVE-2025-37175.