Executive brief
HPE EdgeConnect SD-WAN Gateways are network devices that manage wide-area network traffic and connectivity. An unauthenticated attacker on the same network segment can crash the gateway, forcing manual restart and disrupting all traffic routing through the device until recovered.
Technical details
This vulnerability allows an unauthenticated adjacent network attacker to trigger a denial of service condition in HPE EdgeConnect SD-WAN Gateways. The attack vector is adjacent-network, meaning the attacker must be on the same network segment as the affected device. Successful exploitation causes the system to crash and become unable to reboot without manual intervention, effectively disabling the device. No authentication is required to mount the attack. A patch is available from HPE.
Affected products
- HPE EdgeConnect SD-WAN Gateway <UNKNOWN>
Timeline
- 2026-09-15: disclosed