
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-37163 is a command injection vulnerability in the command line interface (CLI) of the HPE Aruba Networking AirWave platform. An authenticated attacker can exploit this flaw to execute arbitrary operating system commands with elevated privileges on the underlying OS. All AirWave versions prior to 8.3.0.5 are affected (CPE: cpe:2.3:a:arubanetworks:airwave:*:*:*:*:*:*:*:*, versions up to and excluding 8.3.0.5). The vulnerability was published on November 18, 2025, with a patch released shortly after. It carries a CVSS v3.1 base score of 7.2 (High) (HPE Advisory, Red Hat CVE).
The root cause is improper neutralization of special elements used in OS commands (CWE-78) and command injection (CWE-77) within the AirWave CLI. An authenticated attacker with high-privilege network access can craft malicious CLI input that is passed unsanitized to the underlying OS, resulting in arbitrary command execution with elevated privileges. The attack vector is network-based, requires no user interaction, and has low attack complexity — the primary barrier is the requirement for prior authentication with high-privilege credentials (HPE Advisory, Red Hat CVE).
Successful exploitation grants an attacker the ability to execute arbitrary OS commands with elevated privileges, resulting in full compromise of confidentiality, integrity, and availability of the affected AirWave system. An attacker could access or exfiltrate sensitive network management data, modify system configurations, disrupt wireless network management operations, and potentially use the compromised host as a pivot point for lateral movement within the managed network environment (HPE Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.27%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with high-privilege credentials, which limits opportunistic exploitation but does not eliminate insider threat or post-compromise scenarios.
;, &&, |, backticks) appended to a legitimate CLI command to inject arbitrary OS commands./bin/sh, bash, curl, wget, nc) that are not part of normal AirWave operations./tmp, /etc/cron.d, SSH authorized_keys files) created by the AirWave service account; presence of web shells or reverse shell scripts.HPE has released a patch in AirWave version 8.3.0.5; all users should upgrade immediately from any version in the 8.3.0.0–8.3.0.4 range (HPE Advisory). As interim mitigations, organizations should restrict CLI access to trusted administrators only, enforce strong multi-factor authentication for administrative accounts, and ensure the AirWave management interface is not exposed to untrusted networks. Monitoring and logging of all CLI activity is also recommended to detect potential exploitation attempts.
The vulnerability was referenced in CISA's weekly vulnerability bulletin for the week of November 17, 2025, and noted in threat landscape digests (CISA Bulletin). No significant independent researcher commentary, vendor statements beyond the HPE advisory, or notable social media discussion has been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."