Impact
A command‑line interface in Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways allows authenticated users with high privileges to inject shell commands. The flaw enables arbitrary code execution on the underlying operating system, resulting in full system compromise. With control over the gateway the attacker can exfiltrate traffic, modify routing, and establish a foothold for further attacks.
Affected Systems
Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are impacted. No version range is specified in the advisory, so all devices that still include the vulnerable CLI component are at risk.
Risk and Exploitability
The CVSS base score of 9.1 classifies the vulnerability as critical. The EPSS score is not published, but the absence of a CISA KEV listing does not reduce the risk; the flaw is likely to be actively targeted within breached environments. Exploitation requires authentication and high‑privilege access to the CLI, making it a high‑impact attack vector for internal or compromised administrators.
OpenCVE Enrichment