Description
A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path‑traversal weakness in the web‑based management interface of Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateway (ECOS) lets an attacker who is logged in with high privileges read, modify, or delete any file on the device. The flaw, identified as CWE‑377 and CWE‑732, threatens confidentiality, integrity, and availability of configuration files, logs, and system binaries.

Affected Systems

Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS). The vulnerability affects all build versions of the web UI for ECOS; no specific firmware or model numbers are specified in the advisory.

Risk and Exploitability

The CVSS base score of 7.2 indicates moderate to high severity. The EPSS score of < 1 % shows a low likelihood of exploitation currently, and the vulnerability is not listed in CISA KEV. Exploitation requires remote authenticated access to the web interface, so the attacker must first obtain or guess valid credentials. Once authenticated, the path traversal can be leveraged to reach arbitrary paths, potentially exposing sensitive data and enabling further compromise.

Generated by OpenCVE AI on August 4, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available HPE firmware or patch that resolves the path‑traversal flaw as soon as it becomes available.
  • Restrict the web interface to a trusted internal network or enforce VPN access and apply strict role‑based access controls to limit privileged actions.
  • Enable logging and actively monitor web‑interface activity for anomalous traversal attempts or unauthorized file access, and review logs regularly.

Generated by OpenCVE AI on August 4, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-22

Fri, 24 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-22

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe edgeconnect Sd-wan Gateway
Vendors & Products Hpe
Hpe edgeconnect Sd-wan Gateway

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-377
CWE-732
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.
Title Authenticated Path Traversal allows Unauthorized Access in Web Interface
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hpe Edgeconnect Sd-wan Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-07-23T13:29:55.282Z

Reserved: 2026-05-07T21:29:22.243Z

Link: CVE-2026-44878

cve-icon Vulnrichment

Updated: 2026-07-23T13:28:05.526Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses
  • CWE-377

    Insecure Temporary File

  • CWE-732

    Incorrect Permission Assignment for Critical Resource