← back
CVE-2025-37125

Broken access control vulnerability in Firewall Configuration Leads to Unauthorized Access to Internal Network Resources

CVSS 7.5 HIGHEPSS 0.3%CWE-284
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →