Description
A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures.
References (1)
Core 1
Core References
Scores
CVSS v3
6.7
EPSS
0.0020
EPSS Percentile
10.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WAN Gateway
9.4.0.0 - 9.4.3.7
Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WAN Gateway
9.5.0.0 - 9.5.3.6
Published
Sep 16, 2025
Tracked Since
Feb 18, 2026