CVE-2025-37157: HPE Arubaos-Cx

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

Affected products

  • HPE Arubaos-Cx: from 10.10.0000, before 10.10.1170 (fixed in 10.10.1170); from 10.13.0000, before 10.13.1101 (fixed in 10.13.1101); from 10.14.0000, before 10.14.1060 (fixed in 10.14.1060); from 10.15.0000, before 10.15.1030 (fixed in 10.15.1030); from 10.16.0000, before 10.16.1001 (fixed in 10.16.1001)

Published 2025-11-18. Last modified 2026-06-17.