CVE-2025-37169: Arubanetworks Arubaos
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.
Affected products
- Arubanetworks Arubaos: from 10.3.0.0, before 10.4.1.10 (fixed in 10.4.1.10); from 10.5.0.0, before 10.7.2.2 (fixed in 10.7.2.2)
Published 2026-01-13. Last modified 2026-06-17.