← back
CVE-2025-37139mediumCWE-400

Vulnerability in AOS firmware allows for Authenticated Local malicious actor to Permanently Disable Boot

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H