Hewlett Packard Enterprise (HPE Aruba Networking) disclosed and patched multiple high-severity vulnerabilities affecting Aruba Networking Instant On access points/routers, warning that devices running software 3.3.1.0 and earlier are exposed to information disclosure and denial-of-service (DoS) conditions. The most notable issues include CVE-2025-37165 (CVSS 7.5), which can expose VLAN and other internal network configuration details via unintended interfaces when operating in router mode, and CVE-2025-37166 (CVSS 7.5), where specially crafted packets can drive devices into a non-responsive state that may require a hard reset to restore service. HPE also addressed kernel-level packet-processing weaknesses (CVE-2023-52340 and CVE-2022-48839) tied to IPv4/IPv6 handling that can lead to memory corruption and service disruption.
Separately, HPE Aruba issued an advisory for ArubaOS AOS-8 and AOS-10 used by Mobility Conductors, Controllers, and Gateways, patching a broader set of vulnerabilities spanning authenticated command injection and web-interface flaws. The highest-impact item highlighted is CVE-2025-37168 (CVSS 8.2), an unauthenticated arbitrary file deletion vulnerability in AOS-8 Mobility Conductors that can delete critical files and trigger a DoS condition; additional fixes include an authenticated web management interface stack overflow in AOS-10 (CVE-2025-37169) that can enable privileged code execution, plus multiple authenticated command injection and file upload/write issues across AOS-8/AOS-10.

See affected versions and whether adversaries are exploiting it.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.