CVE-2025-37164
CRITICAL KEV NUCLEIHPE OneView unauthenticated RCE
Title source: metasploitExploitation Summary
CVE-2025-37164 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 7, 2026.
EIP tracks 5 public exploits from researchers including g0vguy, adminlove520, rxerium, including a Metasploit module exploits/linux/http/hpe_oneview_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This is a functional PoC for CVE-2025-37164, an unauthenticated RCE vulnerability in HPE OneView. It includes API version brute-forcing and command execution capabilities.
Description
A remote code execution issue exists in HPE OneView.
Exploits (5)
This is a functional PoC for CVE-2025-37164, an unauthenticated RCE vulnerability in HPE OneView. It includes API version brute-forcing and command execution capabilities.
This repository contains a functional Python exploit for CVE-2025-37164, targeting HPE OneView's unauthenticated RCE vulnerability via the `/rest/id-pools/executeCommand` endpoint. The exploit includes API version brute-forcing, command execution, and reverse shell capabilities.
This repository provides a Nuclei template for detecting potentially vulnerable HPE OneView instances (CVE-2025-37164) by checking version numbers. It does not include an exploit but helps identify targets for further testing.
This Python script exploits CVE-2025-37164 in HPE OneView by sending a crafted PUT request to execute arbitrary commands via the `/rest/id-pools/executeCommand` endpoint. It requires no authentication and directly injects user-provided commands into the payload.
This Metasploit module exploits CVE-2025-37164, an unauthenticated RCE vulnerability in HPE OneView versions below 11.00. It leverages a vulnerable 'ID Pools' endpoint to execute arbitrary commands via a PUT request with JSON payload.
Nuclei Templates (1)
html:"HPE" html:"OneView"
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H