Executive brief
HPE EdgeConnect SD-WAN Gateways are appliances that manage network traffic and secure connections across distributed locations. A buffer overflow vulnerability in the underlying operating system allows unauthenticated attackers on the network to execute arbitrary code, potentially giving them complete control over the device and the traffic it handles.
Technical details
A buffer overflow vulnerability exists in the underlying operating system of HPE EdgeConnect SD-WAN Gateways. The flaw is remotely exploitable without authentication, allowing an attacker to send specially crafted network packets that overflow a buffer and overwrite adjacent memory. Successful exploitation enables arbitrary code execution with the privileges of the vulnerable service, leading to complete system compromise. No authentication is required; the attacker must have network access to the appliance.
Affected products
- HPE EdgeConnect SD-WAN Gateway <UNKNOWN>
Timeline
- 2026-09-15: disclosed
- other: No evidence of active exploitation in the wild