CVE-2025-37168

HIGH

Mobility Conductors <AOS-8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in denial-of-service conditions on affected devices.

Scores

CVSS v3 8.2
EPSS 0.0008
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (1)
arubanetworks/arubaos 6.5.4.0 - 8.10.0.21
Published Jan 13, 2026
Tracked Since Feb 18, 2026