CVE-2025-37163

A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying operating system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:*

History

03 Dec 2025, 13:34

Type Values Removed Values Added
CWE CWE-77
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04971en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04971en_us&docLocale=en_US - Vendor Advisory
First Time Arubanetworks
Arubanetworks airwave
CPE cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:*

01 Dec 2025, 16:15

Type Values Removed Values Added
CWE CWE-78

18 Nov 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 19:15

Updated : 2025-12-03 13:34


NVD link : CVE-2025-37163

Mitre link : CVE-2025-37163

CVE.ORG link : CVE-2025-37163


JSON object : View

Products Affected

arubanetworks

  • airwave
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')