A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system. | |
| Title | Authenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLI | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-11-19T04:55:38.634Z
Reserved: 2025-04-16T01:28:25.375Z
Link: CVE-2025-37163
No data.
Status : Awaiting Analysis
Published: 2025-11-18T19:15:48.290
Modified: 2025-11-19T19:14:59.327
Link: CVE-2025-37163
No data.
OpenCVE Enrichment
No data.