CVE-2025-37147: Hewlett Packard Enterprise HPE Arubaos Aos
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on affected Access Points.
Affected products
- Hewlett Packard Enterprise HPE Arubaos Aos: from 10.7.0.0, up to and including 10.7.1.1; from 10.4.0.0, up to and including 10.4.1.8; from 8.13.0.0, up to and including 8.13.0.1; from 8.12.0.0, up to and including 8.12.0.5; from 8.10.0.0, up to and including 8.10.0.18
Published 2025-10-14. Last modified 2026-10-08.