Executive brief
A security vulnerability has been identified in the management interface of HPE EdgeConnect SD-WAN Gateways, which are used to manage corporate wide-area networks. An attacker with high-level administrative credentials could exploit this flaw to access the device's internal filesystem. This could lead to the theft of sensitive configuration files or the unauthorized modification and deletion of critical system data, potentially disrupting network operations.
Technical details
A filesystem access vulnerability exists in the web-based management interface of HPE EdgeConnect SD-WAN Gateway (ECOS). The flaw allows a remote attacker with high privileges (PR:H) to bypass intended access restrictions and interact directly with the underlying filesystem. The attack vector is network-based and requires no user interaction. Once exploited, the attacker can read sensitive system files or perform unauthorized write/delete operations, compromising the integrity and confidentiality of the gateway. Affected versions include the 9.4.x, 9.5.x, and 9.6.x branches up to 9.6.1.0.
Affected products
- HPE EdgeConnect SD-WAN Gateway (ECOS) 9.4.0.0 through 9.4.6.0, 9.5.0.0 through 9.5.6.0, 9.6.0.0 through 9.6.1.0
Timeline
- 2026-07-21: advisory: Initial disclosure by HPE and NVD publication