SB2026011551 - Multiple vulnerabilities in HPE ArubaOS (AOS)



SB2026011551 - Multiple vulnerabilities in HPE ArubaOS (AOS)

Published: January 15, 2026

Security Bulletin ID SB2026011551
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 12
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 25% Low 75%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 12 vulnerabilities.


1) OS command injection (CVE-ID: CVE-2025-37176)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote privileged user can alter a package header to inject and execute arbitrary shell commands.


2) Out-of-bounds read (CVE-ID: CVE-2025-37179)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a boundary condition. A remote non-authenticated attacker can send specially crafted data to the system, trigger an out-of-bounds read error and perform a denial of service attack.


3) Out-of-bounds read (CVE-ID: CVE-2025-37178)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to a boundary condition. A remote non-authenticated attacker can send specially crafted data to the system, trigger an out-of-bounds read error and perform a denial of service attack.


4) OS command injection (CVE-ID: CVE-2025-37177)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a local user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the command-line interface of mobility conductors. A local privileged user can execute arbitrary OS commands on the target system.


5) Arbitrary file upload (CVE-ID: CVE-2025-37175)

CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload in the web-based management interface of mobility conductors. A remote privileged user can upload a malicious file and execute it on the server.


6) Missing authorization (CVE-ID: CVE-2025-37168)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to delete arbitrary files on the system.

The vulnerability exists due to missing authorization checks. A remote non-authenticated attacker can send a specially crafted request to the system and delete arbitrary files, leading to denial of service conditions. 


7) Arbitrary file upload (CVE-ID: CVE-2025-37174)

CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload in the web-based management interface of mobility conductors. A remote privileged user can upload a malicious file and execute it on the server.


8) Input validation error (CVE-ID: CVE-2025-37173)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface of mobility conductors. A remote privileged user can send specially crafted input to the system and execute arbitrary code.


9) OS command injection (CVE-ID: CVE-2025-37172)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the web-based management interface of mobility conductors. A remote privileged user can send a specially crafted HTTP request to the system and execute arbitrary OS commands.


10) OS command injection (CVE-ID: CVE-2025-37171)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the web-based management interface of mobility conductors. A remote privileged user can send a specially crafted HTTP request to the system and execute arbitrary OS commands.


11) OS command injection (CVE-ID: CVE-2025-37170)

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the web-based management interface of mobility conductors. A remote privileged user can send a specially crafted HTTP request to the system and execute arbitrary OS commands.


12) Stack-based buffer overflow (CVE-ID: CVE-2025-37169)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the web-based management interface Mobility Gateway. A remote privileged user can send a specially crafted request to the system, trigger a stack-based buffer overflow and execute arbitrary code.



Remediation

Install update from vendor's website.