CVE-2025-37091 is a critical command injection remote code execution vulnerability affecting HPE StoreOnce Software. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not yet in the KEV catalog, its high FAUCET Risk Score of 88/100 indicates significant potential danger. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage are minimal, suggesting it is not yet widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.11CPE matchmatch criteria | cpe:2.3:a:hpe:storeonce_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.