HPE Aruba Networking EdgeConnect OS是美国HPE公司的一个操作系统。 HPE Aruba Networking EdgeConnect OS存在安全漏洞,该漏洞源于基于Web的管理接口存在任意文件写入漏洞,可能导致上传任意文件和执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | ArubaOS (AOS) | 10.7.0.0 ~ 10.7.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-37146 | 7.2 HIGH | Unauthorized Filesystem Operations in System Firmware allow Authenticated Remote Code Exec |
| CVE-2025-37133 | 7.2 HIGH | Authenticated Command Injection Vulnerability in AOS-8 Controller/Mobility Conductor Web-B |
| CVE-2025-37134 | 7.2 HIGH | Authenticated Command Injection Vulnerability in the Low-Level Interface Library Affecting |
| CVE-2025-37147 | 7.1 HIGH | Secure Boot Bypass allows for Compromise of Hardware Root of Trust |
| CVE-2025-37137 | 6.5 MEDIUM | Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conduct |
| CVE-2025-37136 | 6.5 MEDIUM | Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conduct |
| CVE-2025-37135 | 6.5 MEDIUM | Authenticated Arbitrary File Deletion Vulnerabilities in AOS-8 Controller/Mobility Conduct |
| CVE-2025-37148 | 6.5 MEDIUM | Kernel Panic triggered by Modified Ethernet Frames leads to Denial of Service Vulnerabilit |
| CVE-2025-37138 | 6.2 MEDIUM | Authenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Control |
| CVE-2025-37149 | 6.0 MEDIUM | HPE ProLiant RL300 Gen11 Server 安全漏洞 |
| CVE-2025-37139 | 6.0 MEDIUM | Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanentl |
| CVE-2025-37140 | 4.9 MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mo |
| CVE-2025-37141 | 4.9 MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mo |
| CVE-2025-37142 | 4.9 MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in CLI Binary of AOS-8 Controller/Mo |
| CVE-2025-37143 | 4.9 MEDIUM | Authenticated Arbitrary File Download Vulnerability in CLI Binary of AOS-10 GW and AOS-8 C |
| CVE-2025-37144 | 4.9 MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Aff |
| CVE-2025-37145 | 4.9 MEDIUM | Authenticated Arbitrary File Download Vulnerabilities in a Low-Level Interface Library Aff |
No comments yet