VYPR
Unrated severityNVD Advisory· Published Nov 18, 2025· Updated Feb 26, 2026

Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX

CVE-2025-37158

Description

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

Affected products

2
  • Aruba/AOS-CXllm-create
  • Hewlett Packard Enterprise (HPE)/HPE Aruba Networking AOS-CXv5
    Range: 10.16.0000

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.