An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.
History

Tue, 14 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Oct 2025 17:00:00 +0000

Type Values Removed Values Added
Description An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.
Title Authenticated Remote Code Execution Vulnerability in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File Write
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-10-14T19:17:00.979Z

Reserved: 2025-04-16T01:28:25.367Z

Link: CVE-2025-37132

cve-icon Vulnrichment

Updated: 2025-10-14T19:16:56.076Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-14T17:15:39.737

Modified: 2025-10-14T20:15:34.640

Link: CVE-2025-37132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.