CVE-2025-37132

HIGH

Arubanetworks Arubaos < 8.10.0.19 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.

Scores

CVSS v3 7.2
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
arubanetworks/arubaos 8.10.0.0 - 8.10.0.19
Published Oct 14, 2025
Tracked Since Feb 18, 2026