Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5Aruba

Medium [CVE-2025-37148] vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could

A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.

CVE-2025-37148
AOS-10Instant APWireless & ControllersInstant
Oct 14, 2025
Medium4.9Aruba

Medium [CVE-2025-37145] Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility…

Arbitrary file download vulnerabilities exist in a low-level interface library in AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

CVE-2025-37145
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium4.9Aruba

Medium [CVE-2025-37143] arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility…

An arbitrary file download vulnerability exists in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated malicious actor to download arbitrary files through carefully constructed exploits.

CVE-2025-37143
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium4.9Aruba

Medium [CVE-2025-37142] Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating…

Arbitrary file download vulnerabilities exist in the CLI binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to download arbitrary files through carefully constructed exploits.

CVE-2025-37142
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium6.2Aruba

Medium [CVE-2025-37138] authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8…

An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-37138
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Oct 14, 2025
Medium6.5Aruba

Medium [CVE-2025-37137] Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility…

Arbitrary file deletion vulnerabilities have been identified in the command-line interface of an AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated remote malicious actor to delete arbitrary files within the affected system.

CVE-2025-37137
AOS-8 MobilityWireless & ControllersMobility ConductorArubaOS
Oct 14, 2025
High7.2Aruba

High [CVE-2025-37127] vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access and control over the affected systems.

CVE-2025-37127
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2025-37126] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.

CVE-2025-37126
EdgeConnect SD-WAN
Sep 16, 2025
High7.5Aruba

High [CVE-2025-37125] EdgeConnect: broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS).

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

CVE-2025-37125
EdgeConnect SD-WAN
Sep 16, 2025
High8.8Aruba

High [CVE-2025-37123] vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVE-2025-37123
EdgeConnect SD-WAN
Sep 16, 2025
Medium4.9Aruba

Medium [CVE-2025-37131] vulnerability in EdgeConnect SD-WAN ECOS could

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.

CVE-2025-37131
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.5Aruba

Medium [CVE-2025-37130] vulnerability in the command-line interface of EdgeConnect SD-WAN could

A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying file system.

CVE-2025-37130
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.7Aruba

Medium [CVE-2025-37129] vulnerable feature in the command line interface of EdgeConnect SD-WAN could

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures.

CVE-2025-37129
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.8Aruba

Medium [CVE-2025-37128] vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.

CVE-2025-37128
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2025-27083] Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based…

Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2025-27083
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Apr 8, 2025
High7.2Aruba

High [CVE-2025-27082] Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8…

Arbitrary File Write vulnerabilities exist in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an Authenticated attacker to upload arbitrary files and execute arbitrary commands on the underlying host operating system.

CVE-2025-27082
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Apr 8, 2025
Medium4.9Aruba

Medium [CVE-2025-27085] Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor

Multiple vulnerabilities exist in the web-based management interface of AOS-10 GW and AOS-8 Controller/Mobility Conductor. Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.

CVE-2025-27085
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Apr 8, 2025
Medium5.4Aruba

Medium [CVE-2025-27084] vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could

A vulnerability in the Captive Portal of an AOS-10 GW and AOS-8 Controller/Mobility Conductor could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack. Successful exploitation could enable the attacker to execute arbitrary script code in the victim's browser within the context of the affected interface.

CVE-2025-27084
AOS-10AOS-8 MobilityWireless & ControllersMobility Conductor
Apr 8, 2025
Medium6.0Aruba

Medium [CVE-2025-27079] vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could

A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating system leading to potential system compromise.

CVE-2025-27079
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025
Medium6.5Aruba

Medium [CVE-2025-27078] vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could

A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.

CVE-2025-27078
AOS-10Instant APWireless & ControllersInstant
Apr 8, 2025