Impact
The vulnerability is a command injection flaw in the command line interface of Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways. An authenticated attacker with high‑privilege access can inject arbitrary shell commands and execute them on the underlying operating system, resulting in full compromise of the gateway. The attacker could modify routing, exfiltrate traffic, or leverage the device as a foothold for additional attacks. The weakness is an unchecked shell command injection (CWE‑77).
Affected Systems
HPE EdgeConnect SD‑WAN Gateways are affected. The advisory does not specify a vulnerable version range, indicating that any gateway still containing the vulnerable CLI component is at risk. All devices running the current firmware or software without the patch should be considered vulnerable.
Risk and Exploitability
With a CVSS base score of 9.1 the flaw is classified as critical. The EPSS score of 0.01342 (approximately 1%) indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires authenticated high‑privilege access, implying the exploitation likely originates from an internal or compromised administrator account. In such scenarios the risk is high because the attacker could alter routing or gain full back‑door access. Despite the low EPSS, the potential impact warrants immediate mitigation.
OpenCVE Enrichment