A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.
History

Tue, 08 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.
Title Authenticated Remote Command Execution caused by Insecure Function Usage in System Binary
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published: 2025-04-08T15:57:02.519Z

Updated: 2025-04-09T04:00:46.758Z

Reserved: 2025-02-18T14:05:41.921Z

Link: CVE-2025-27078

cve-icon Vulnrichment

Updated: 2025-04-08T16:57:25.237Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T16:15:25.683

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-27078

cve-icon Redhat

No data.