CVE-2025-37168
Unauthenticated Arbitrary File Deletion Vulnerability in AOS-8 Operating System
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 8.2EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 jan 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 operating system. Successful exploitation of this vulnerability could allow an unauthenticated remote malicious actor to delete arbitrary files within the affected system and potentially result in denial-of-service conditions on affected devices.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Produtos afetados
Hewlett Packard Enterprise (HPE) · ArubaOS (AOS)Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →