All 34 CVE vulnerabilities found in ArubaOS (AOS), with AI-generated Chinese analysis, references, and POCs.
This page aggregates security vulnerabilities affecting ArubaOS (AOS), a network operating system developed by Aruba (now Hewlett Packard Enterprise). It compiles known security flaws specific to this platform, covering a defined historical timeframe of disclosed issues. Readers can track Aruba's published security advisories, analyze the prevalence of specific weakness classes such as buffer overflows or authentication bypasses, and review the product's complete vulnerability history to assess long-term security trends.
Vendor: Hewlett Packard Enterprise (HPE)
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-37132 | Authenticated Remote Code Execution Vulnerability in AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface via Arbitrary File Write | 7.2 | High | 2025-10-14 |
| CVE-2025-37148 | Kernel Panic triggered by Modified Ethernet Frames leads to Denial of Service Vulnerability | 6.5 | Medium | 2025-10-14 |
| CVE-2025-37147 | Secure Boot Bypass allows for Compromise of Hardware Root of Trust | 7.1 | High | 2025-10-14 |
| CVE-2025-37146 | Unauthorized Filesystem Operations in System Firmware allow Authenticated Remote Code Execution | 7.2 | High | 2025-10-14 |
All 34 known CVE vulnerabilities affecting ArubaOS (AOS) with full Chinese analysis, references, and POCs where available.