CVE-2025-37133: Authenticated Command Injection Vulnerability in AOS-8 Controller/Mobility Conductor Web-Based Management Interface via the CLI Binaryalong with accounting controls for tracking and logging user activities and resource usage.
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37133?
CVE-2025-37133 is considered a high severity vulnerability due to its potential for command injection by authenticated users.
How do I fix CVE-2025-37133?
To fix CVE-2025-37133, update the AOS-8 Controller/Mobility Conductor to the latest patched version provided by Arista.
What systems are affected by CVE-2025-37133?
CVE-2025-37133 affects the AOS-8 Controller and Mobility Conductor operating system from Arista Networks.
Can CVE-2025-37133 be exploited remotely?
CVE-2025-37133 requires authenticated access, meaning it cannot be exploited remotely without valid credentials.
What are the potential impacts of CVE-2025-37133?
Successful exploitation of CVE-2025-37133 could allow an authenticated attacker to execute arbitrary commands with privileged access on the underlying operating system.