A critical remote code execution vulnerability, identified as CVE-2025-37164 and assigned a maximum CVSS score of 10.0, has been discovered in HPE OneView. The flaw allows unauthenticated attackers to execute arbitrary code remotely, potentially granting them total control over data center infrastructure managed by affected HPE OneView deployments. The vulnerability is remotely exploitable and does not require authentication, significantly increasing the risk to organizations using this management platform.
Security advisories highlight the severity of the issue, noting that exploitation could lead to full compromise of data center environments. While specific affected versions have not yet been detailed, organizations are urged to monitor official HPE communications and apply mitigations or patches as soon as they become available to prevent unauthorized access and potential disruption of critical infrastructure.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Researchers later published broader exploit tooling for the flaw, including a Metasploit module targeting the vulnerable ID-Pools executeCommand functionality. This made exploitation more accessible to a wider range of attackers.
A proof-of-concept exploit for CVE-2025-37164 was publicly released, showing how the hidden ID Pools API could be abused for unauthenticated remote code execution. Its publication significantly increased the likelihood of real-world exploitation.
Multiple reports stated that, as of disclosure, HPE had not confirmed active exploitation of CVE-2025-37164 in the wild. At the same time, vendors and researchers warned that the flaw's severity and ease of exploitation made urgent remediation necessary.
Rapid7 Labs confirmed the attack vector as the unauthenticated /rest/id-pools/executeCommand endpoint in HPE OneView. The company also released detection capabilities for customers to help identify exploitation attempts.
HPE disclosed CVE-2025-37164, a critical unauthenticated remote code execution flaw in OneView with a CVSS score of 10.0. The company released OneView 11.00 and hotfixes for affected versions, urging customers to patch immediately.
Security researcher Nguyen Quoc Khanh (also referenced as brocked200) responsibly disclosed CVE-2025-37164 to HPE. The disclosure date is explicitly reported as December 16, 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceattackerkb.com
Open sourcesocradar.io
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.