CVE-2025-37164

CRITICAL KEV NUCLEI

HPE OneView unauthenticated RCE

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2025-37164 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 7, 2026. EIP tracks 5 public exploits from researchers including g0vguy, adminlove520, rxerium, including a Metasploit module exploits/linux/http/hpe_oneview_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This is a functional PoC for CVE-2025-37164, an unauthenticated RCE vulnerability in HPE OneView. It includes API version brute-forcing and command execution capabilities.

Description

A remote code execution issue exists in HPE OneView.

Exploits (5)

nomisec WORKING POC 6 stars
by g0vguy · remote
https://github.com/g0vguy/CVE-2025-37164-PoC

This is a functional PoC for CVE-2025-37164, an unauthenticated RCE vulnerability in HPE OneView. It includes API version brute-forcing and command execution capabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HPE OneView (versions affected by CVE-2025-37164)
No auth needed
Prerequisites: Network access to HPE OneView instance · Vulnerable API endpoint exposed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-37164

This repository contains a functional Python exploit for CVE-2025-37164, targeting HPE OneView's unauthenticated RCE vulnerability via the `/rest/id-pools/executeCommand` endpoint. The exploit includes API version brute-forcing, command execution, and reverse shell capabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HPE OneView
No auth needed
Prerequisites: network access to target · vulnerable HPE OneView instance
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec SCANNER 2 stars
by rxerium · poc
https://github.com/rxerium/CVE-2025-37164

This repository provides a Nuclei template for detecting potentially vulnerable HPE OneView instances (CVE-2025-37164) by checking version numbers. It does not include an exploit but helps identify targets for further testing.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: HPE OneView < 11.00 (or versions 5.20-10.20 without Z7550-98077 hotfix)
No auth needed
Prerequisites: Nuclei installed · Network access to target HPE OneView instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by LACHHAB-Anas · remote
https://github.com/LACHHAB-Anas/Exploit_CVE-2025-37164

This Python script exploits CVE-2025-37164 in HPE OneView by sending a crafted PUT request to execute arbitrary commands via the `/rest/id-pools/executeCommand` endpoint. It requires no authentication and directly injects user-provided commands into the payload.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: HPE OneView (version not specified)
No auth needed
Prerequisites: Network access to the target HPE OneView instance · Target must be vulnerable to CVE-2025-37164
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Nguyen Quoc Khanh, remmons-r7, sfewer-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/hpe_oneview_rce.rb

This Metasploit module exploits CVE-2025-37164, an unauthenticated RCE vulnerability in HPE OneView versions below 11.00. It leverages a vulnerable 'ID Pools' endpoint to execute arbitrary commands via a PUT request with JSON payload.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HPE OneView < 11.00
No auth needed
Prerequisites: Network access to HPE OneView management interface · Vulnerable 'ID Pools' endpoint enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

HPE OneView - Remote Code Execution
CRITICALVERIFIEDby DhiyaneshDk,garciaizcoa
Shodan: html:"HPE" html:"OneView"

Scores

CVSS v3 10.0
EPSS 0.7857
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-01-07
VulnCheck KEV 2025-12-24
ENISA EUVD EUVD-2025-203803
CWE
CWE-94
Status published
Products (1)
hpe/oneview < 10.20.00
Published Dec 16, 2025
KEV Added Jan 07, 2026
Tracked Since Feb 18, 2026