CVE-2025-37176
Command Injection in AOS-8 Allows Privileged Command Execution
Publication date: 2026-01-13
Last updated on: 2026-01-13
Assigner: Hewlett Packard Enterprise (HPE)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hpe | aos-8 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-77 | The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a command injection flaw in AOS-8 that allows an authenticated privileged user to modify a package header to inject shell commands. This means that an attacker with valid credentials and high privileges can execute arbitrary commands within the system, potentially manipulating internal operations.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an authenticated malicious actor to execute commands with the privileges of the affected mechanism, potentially leading to unauthorized control over system operations and compromising system integrity.