CVE-2025-37161 Details
Description
A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
A denial-of-service vulnerability has been identified in the web-based management interface of the HPE Aruba Networking 100 Series Cellular Bridge, specifically in versions AOS-10.7.1.1 and below. This vulnerability allows an unauthenticated remote attacker to crash the system, disrupt network operations, and cause the device to fail to reboot without manual intervention.
Users are advised to upgrade the HPE Aruba Networking 100 Series Cellular Bridge firmware to version AOS-10.7.2.0 or above. This vulnerability can be downloaded from the HPE Networking Support Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04970en_us&docLocale=en_US | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| arubanetworks arubaos | < 10.7.2.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 13, 2026 | Initial Analysis | [email protected] |
| Nov 19, 2025 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | New CVE Received | [email protected] |