CVE-2025-37147: Hewlett Packard Enterprise HPE Arubaos Aos

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on affected Access Points.

Affected products

  • Hewlett Packard Enterprise HPE Arubaos Aos: from 10.7.0.0, up to and including 10.7.1.1; from 10.4.0.0, up to and including 10.4.1.8; from 8.13.0.0, up to and including 8.13.0.1; from 8.12.0.0, up to and including 8.12.0.5; from 8.10.0.0, up to and including 8.10.0.18

Published 2025-10-14. Last modified 2026-10-08.