CVE-2025-37147 Details
Description
A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on affected Access Points.
A secure boot bypass vulnerability has been identified in HPE Aruba Networking access points running AOS-8 Instant and AOS-10 AP. This vulnerability allows an adversary to bypass the hardware root of trust verification, which is designed to ensure that only vendor-signed firmware can be executed on the device. Exploitation of this vulnerability could enable the execution of modified or custom firmware on the affected access points.
Users are advised to upgrade to AOS-10 AP 10.7.x.x version 10.7.2.0 and above, AOS-10 AP 10.4.x.x version 10.4.1.8 and above, AOS-8 Instant 8.13.x.x version 8.13.1.0 and above, AOS-8 Instant 8.12.x.x version 8.12.0.6 and above, or AOS-8 Instant 8.10.x.x version 8.10.0.17 and above. For assistance, contact HPE Services - Aruba Networking.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 14, 2025CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04958en_us&docLocale=en_US | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| HPE Aruba Access Points | All versions |
CPE
Remediation
| |
| HPE Aruba AOS-8 Instant | All versions |
CPE
Remediation
| |
| HPE Aruba AOS-10 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | New CVE Received | [email protected] |
Volerion