CVE-2025-37148: Hewlett Packard Enterprise HPE Arubaos Aos

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.

Affected products

  • Hewlett Packard Enterprise HPE Arubaos Aos: from 10.7.0.0, up to and including 10.7.1.1; from 10.4.0.0, up to and including 10.4.1.8; from 8.13.0.0, up to and including 8.13.0.1; from 8.12.0.0, up to and including 8.12.0.5; from 8.10.0.0, up to and including 8.10.0.18

Published 2025-10-14. Last modified 2026-10-08.