Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-37164 | Unauthenticated Remote Code Execution in HPE OneView HPE OneView, HPE's infrastructure management platform, contains a code-injection flaw (CWE-94) that permits unauthenticated remote code execution, with a network-vector, low-complexity CVSS 3.1 score of 9.8 meaning no credentials, privileges, or user interaction are required. An attacker triggers the flaw by sending crafted code-injection input to the OneView appliance over the network, gaining code execution with high impact on the confidentiality, integrity, and availability of the appliance. A compromised OneView instance can serve as a foothold into the HPE server estate it manages, and the RondoDox botnet has already been observed folding this flaw into its exploitation waves. Any organization running an HPE OneView appliance is affected, particularly where the appliance is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, a public Metasploit exploit module is available, and EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile). Do: Upgrade OneView to the fixed release specified in the HPE security bulletin for CVE-2025-37164 (exact version numbers are not included in this data), and treat patching as urgent given confirmed in-the-wild exploitation and the public Metasploit module. Until patched, remove unnecessary internet exposure of the OneView appliance and review appliance and network logs for signs of compromise, including possible RondoDox botnet infection. US federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable. | 9.8 | 90% | KEV PoC |
| large≈ tens of thousands of deployed OneView appliance instances worldwide, with the internet-exposed subset likely in the thousands |
Full article319 words · extracted from helpnetsecurity.com · click to collapse
An unauthenticated remote code execution vulnerability (CVE-2025-37164) affecting certain versions of HPE OneView is being leveraged by attackers, CISA confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog.

The vulnerability’s inclusion in the catalog is unsurprising, as technical details and a Metasploit module were made public soon after it was disclosed, making exploitation by less-skilled attackers easier.
About HPE OneView and CVE-2025-37164
HPE OneView is a centralized infrastructure management platform used to deploy, monitor, and manage HPE data center hardware and software from a single interface.
The solution is popular in large-scale and automated data center environments.
“OneView sits at a privileged control plane for enterprise infrastructure, so successful exploitation isn’t just about establishing remote code execution, it’s about gaining centralized control over servers, firmware, and lifecycle management at scale,” Rapid7 researchers explained.
“Management platforms are often deployed deep inside the network with broad privileges and minimal monitoring because they’re ‘supposed’ to be trusted. When an unauthenticated RCE shows up in that layer, defenders need to treat it as an assumed-breach scenario, prioritize patching immediately, and review access paths and segmentation.”
CVE-2025-37164 is a code injection vulnerability via an unsecured REST API endpoint and can lead to unauthenticated remote code execution.
CVE-2025-37164 was privately reported by security researcher Nguyen Quoc Khanh and Hewlett Packard Enterprise released hotfixes on December 16, 2025.
Rapid7 researchers analyzed the hotfix and explained how the vulnerability can be triggered. On December 19, a Metasploit module for the flaw was released.
HPE says that OneView versions before v11.0 are vulnerable, and organizations should upgrade to it, as there are no workarounds nor mitigations available.
UPDATE (January 16, 2026, 08:00 a.m. ET):
The vulnerability is being exploited in an automated fashion by the Linux-based RondDox botnet, Check Point Research reported.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/01/08/hpe-oneview-cve-2025-37164-exploited/