All 5 CVE vulnerabilities found in HPE Aruba Networking AOS-CX, with AI-generated Chinese analysis, references, and POCs.
Vendor: Hewlett Packard Enterprise (HPE)
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-37160 | Authenticated Broken Access Control (BAC) in REST API Configuration Service | 5.3 | Medium | 2025-11-18 |
| CVE-2025-37159 | Authenticated Session Hijacking Allows Unauthorized Access in Network Switching Software | 5.8 | Medium | 2025-11-18 |
| CVE-2025-37158 | Authenticated Command Injection allows Unauthorized Command Execution in AOS-CX | 6.7 | Medium | 2025-11-18 |
| CVE-2025-37156 | ArubaOS-CX Platform-Level Denial-of-Service Vulnerability | 6.8 | Medium | 2025-11-18 |
| CVE-2025-37155 | Authenticated Privilege Escalation Allows Unauthorized Access in Network Management Interface | 7.8 | High | 2025-11-18 |
All 5 known CVE vulnerabilities affecting HPE Aruba Networking AOS-CX with full Chinese analysis, references, and POCs where available.