CVE-2025-37176
MEDIUMArubaOS 8.6.0.0-8.10.0.21 - Authenticated Command Injection via Package Header
Title source: llmDescription
A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism.
References (1)
Core 1
Core References
Scores
CVSS v3
6.5
EPSS
0.0007
EPSS Percentile
22.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-77
Status
published
Products (1)
arubanetworks/arubaos
8.6.0.0 - 8.10.0.21
Published
Jan 13, 2026
Tracked Since
Feb 18, 2026