A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism.
References
| Link | Resource |
|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04987en_us&docLocale=en_US | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Jan 2026, 16:12
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Arubanetworks
Arubanetworks arubaos |
|
| CPE | cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* | |
| References | () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04987en_us&docLocale=en_US - Vendor Advisory |
13 Jan 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-77 |
13 Jan 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 20:16
Updated : 2026-01-23 16:12
NVD link : CVE-2025-37176
Mitre link : CVE-2025-37176
CVE.ORG link : CVE-2025-37176
JSON object : View
Products Affected
arubanetworks
- arubaos
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
