CVE-2025-37177

EUVD-2026-2049
An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
hpeCNA
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
arubanetworksarubaos
6.5.4.0 ≤
𝑥
< 8.10.0.21
arubanetworksarubaos
8.11.0.0 ≤
𝑥
< 8.13.1.1
arubanetworksarubaos
10.3.0.0 ≤
𝑥
< 10.4.1.10
arubanetworksarubaos
10.5.0.0 ≤
𝑥
< 10.7.2.2
𝑥
= Vulnerable software versions