Executive brief
HPE Networking EdgeConnect SD-WAN Gateways include a web-based management interface used to configure and monitor network traffic control. A buffer overflow vulnerability in this interface allows authenticated administrators to crash the system, disrupting network operations and potentially leaving the device in an unstable state that requires manual recovery.
Technical details
A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. The vulnerability requires authentication with administrative privileges and network access to the management interface. Successful exploitation can cause a denial of service by crashing the management process or the entire device. The vulnerability is a classic memory corruption issue that could potentially be leveraged for further exploitation, though current evidence indicates it primarily impacts availability. Patches are available through HPE support.
Affected products
- HPE Networking EdgeConnect SD-WAN Gateways
Timeline
- 2026-09-15: disclosed