CVE-2025-37161

7.5

Hewlett Packard Enterprise · HPE Aruba Networking 100 Series Cellular Bridge

A vulnerability in the web-based management interface of HPE Aruba Networking 100 Series Cellular Bridge devices allows unauthenticated remote attackers to trigger a denial of service.

Executive summary

An unauthenticated remote denial of service vulnerability in HPE Aruba Networking 100 Series Cellular Bridge devices poses a significant risk to network availability.

Vulnerability

This vulnerability resides in the web-based management interface of the affected firmware, allowing an unauthenticated remote attacker to crash the system. Because the system may fail to reboot without manual intervention, this flaw effectively results in a persistent denial of service.

Business impact

The CVSS score of 7.5 indicates a high severity risk, primarily due to the ease of exploitation and the potential for total loss of network connectivity. Successful exploitation causes a complete system crash, resulting in operational downtime that requires physical or manual intervention to remediate. This poses a severe threat to business continuity, particularly for remote or critical infrastructure deployments.

Remediation

Immediate Action: Consult the official Hewlett Packard Enterprise security advisory at https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04970en_us&docLocale=en_US to identify if a firmware update is available for your specific device.

Proactive Monitoring: Monitor network infrastructure for unauthorized access attempts directed at the web management interface and review system logs for unexpected crashes or service interruptions.

Compensating Controls: Restrict access to the web-based management interface by implementing strict firewall rules or VPN requirements, ensuring the interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high impact on availability and the potential for persistent system failure, this vulnerability should be treated as a priority. Administrators must restrict network access to the management interface immediately and apply the vendor-supplied fix as soon as it is confirmed available in the official security bulletin.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by Nicholas Starke, per the CVE Program record.