vulnerability

Aruba ECOS: CVE-2025-37131: Authenticated Arbitrary File Read allows Data Exposure in CLI Interface

Severity
6
CVSS
(AV:N/AC:L/Au:M/C:C/I:N/A:N)
Published
Sep 16, 2025
Added
Sep 17, 2025
Modified
Sep 19, 2025

Description

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.

Solution

aruba-ecos-cve-2025-37131
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.