Executive brief
HPE Networking EdgeConnect SD-WAN Gateways are enterprise appliances used to optimize and secure wide-area network traffic. An authenticated remote attacker can exploit a component vulnerability by sending a specially crafted input, potentially gaining root-level command execution on the gateway. This could allow an attacker to take full control of the network gateway, intercepting or redirecting traffic, and establishing a persistent foothold within the organization's network infrastructure.
Technical details
The vulnerability exists in a component of HPE Networking EdgeConnect SD-WAN Gateways and permits arbitrary command execution. An authenticated remote attacker can exploit this flaw by providing a specially crafted input to the affected component, resulting in remote code execution with root privileges. The attack requires prior authentication to the appliance but no additional user interaction. Successful exploitation grants an attacker complete control over the gateway with the highest privilege level, enabling potential network compromise, data exfiltration, and lateral movement within the organization's infrastructure.
Affected products
- HPE EdgeConnect SD-WAN Gateways
Timeline
- 2026-09-15: disclosed