Back to Database
Status published
Low
CVE-2025-37109
HPE Telco Service Activator, Protection Mechanism Failure
Vulnerability Description
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-37109
Credits & Attribution
No credits recorded in the NVD database.
More from Hewlett Packard Enterprise (HPE)
View All →CVE-2025-37186
Local Privilege Escalation Vulnerability in HPE Aruba Networking Virtual Intranet Access (VIA) Client for Linux
High
7.8
CVE-2025-37185
Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
Medium
5.5
CVE-2025-37184
Unauthenticated Bypass Allows Multi-Factor Authentication Circumvention
Critical
9.8
CVE-2025-37183
Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
High
7.2
CVE-2025-37182
Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
High
7.2
Affected Vendor
Hewlett Packard Enterprise (HPE)
View all reports →Affected Software
HPE Telco Service Activator
Vulnerable Versions:
10.3.0
Timeline
Official Publish:
July 31st, 2025
Last Modified:
August 4th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.