HPE Aruba Networking EdgeConnect SD-WAN Gateways Authenticated Remote Code Execution Vulnerability

Vulnerability

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways allows remote authenticated users to execute arbitrary commands on the underlying host with root privileges. This issue affects EdgeConnect SD-WAN Release Streams 9.5.3.x and below, 9.4.3.x and below, and all versions of 9.2.x.x and older, which are out of maintenance.

Impact

Exploitation of this vulnerability allows for authenticated remote code execution as root on the underlying operating system.

Remediation

Users are advised to upgrade to HPE Aruba Networking EdgeConnect SD-WAN versions 9.5.4.1 or 9.4.4.2. For EdgeConnect SD-WAN Orchestrator, the version must be equal to or greater than the ECOS version running on the gateways.

Added: Sep 16, 2025, 11:21 PM
Updated: Sep 16, 2025, 11:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.9
remediation
7.9
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.