Junglewise Threat Intelligence

CVE-2025-37164: HPE OneView code injection remote code execution

CVE-2025-37164 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-01-07

Vendors: Hewlett Packard Enterprise, Hpe.

Executive brief

HPE OneView, a centralized management platform for data center infrastructure, contains a critical vulnerability that allows unauthorized attackers to execute arbitrary commands. This could lead to a total compromise of the management appliance, potentially allowing attackers to disrupt data center operations or gain access to connected server hardware. This vulnerability is reportedly being exploited in the wild.

Technical details

A code injection vulnerability (CWE-94) exists in HPE OneView due to improper control of generation of code. The flaw allows a remote, unauthenticated attacker to send specially crafted requests over the network to execute arbitrary code on the underlying Linux-based operating system of the appliance. The vulnerability has a CVSS score of 10.0 as it requires no user interaction or privileges and can lead to a full compromise of the management plane. Evidence of active exploitation has been confirmed by CISA, and a Metasploit module is publicly available. Affected versions include those up to and including 10.20.00.

Affected products

  • HPE OneView Up to and including 10.20.00

Timeline

  • 2025-12-16: disclosed: Initial CVE publication by HPE
  • 2025-12-23: other: Metasploit module released
  • 2026-01-07: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-01-07: advisory: HPE vendor advisory updated