CVE-2025-37163

7.2

Hewlett Packard Enterprise · HPE Aruba Networking Airwave

A command injection vulnerability in the HPE Aruba Networking Airwave CLI allows authenticated attackers to execute arbitrary operating system commands with elevated privileges.

Executive summary

A command injection vulnerability in HPE Aruba Networking Airwave allows an authenticated attacker to execute arbitrary OS commands with elevated privileges, posing a severe risk to system integrity.

Vulnerability

This vulnerability is a command injection flaw within the command line interface of the platform. It requires an attacker to possess authenticated access to the system to trigger the execution of arbitrary commands with elevated OS-level privileges.

Business impact

The ability for an authenticated user to execute arbitrary commands with elevated privileges effectively grants full control over the affected appliance. This could lead to total system compromise, unauthorized data exfiltration, or the deployment of persistent malware within the network environment. With a CVSS score of 7.2, the risk is classified as High, reflecting the potential for significant operational disruption and security breach.

Remediation

Immediate Action: Review the official HPE security bulletin (hpesbnw04971en_us) to identify and apply the necessary security updates or configuration changes provided by the vendor.

Proactive Monitoring: Monitor command line interface access logs for unusual or unauthorized command strings and investigate any unexpected administrative activity.

Compensating Controls: Restrict administrative access to the command line interface to only authorized personnel and utilize network segmentation to isolate the Airwave platform from untrusted segments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for full system takeover, administrators should prioritize the remediation of this vulnerability in all affected environments. Consult the vendor advisory immediately to verify the availability of patches or specific mitigation steps and ensure that administrative access controls are strictly enforced to minimize the attack surface.

More Hewlett Packard Enterprise CVEs

Sources

Originally found and disclosed by Michael 'Smolli' Smolinski, per the CVE Program record.