Executive brief
HPE EdgeConnect SD-WAN Gateways manage wide-area network traffic for enterprises. A command injection flaw in the web management interface could allow an authenticated user with limited privileges to execute arbitrary commands on the appliance, potentially disrupting network operations or enabling further compromise.
Technical details
A command injection vulnerability exists in the web-based management interface of HPE EdgeConnect SD-WAN Gateways, where specially crafted input is not properly validated before being passed to system command execution. An authenticated remote attacker with limited access privileges can exploit this through the management interface. Successful exploitation could result in arbitrary command execution with elevated privileges or a denial-of-service condition on the affected appliance. A patch is available from HPE.
Affected products
- HPE Networking EdgeConnect SD-WAN Gateway <UNKNOWN>
Timeline
- 2026-09-15: disclosed