CVE-2025-37176

MEDIUM

ArubaOS 8.6.0.0-8.10.0.21 - Authenticated Command Injection via Package Header

Title source: llm
STIX 2.1

Description

A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicious actor to execute commands with the privileges of the impacted mechanism.

Scores

CVSS v3 6.5
EPSS 0.0007
EPSS Percentile 22.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
arubanetworks/arubaos 8.6.0.0 - 8.10.0.21
Published Jan 13, 2026
Tracked Since Feb 18, 2026