Impact
The vulnerability allows an attacker who can authenticate to a HPE EdgeConnect SD‑WAN gateway to supply specially crafted input that causes the device to execute arbitrary operating‑system commands as root. This flaw is a classic instance of command injection, meaning the attacker can run any command he chooses with the full privileges of the gateway’s most privileged account, yielding complete system control.
Affected Systems
All Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are affected. The advisory does not list specific firmware or hardware revisions, so any deployed gateway at the time should verify its model and operating image against the vendor’s documented fix.
Risk and Exploitability
Exploitation requires valid credentials; once authenticated, the attacker can target the vulnerable input handling component to achieve root‑level command execution. The CVSS score of 7.2 reflects the high impact, while the EPSS score of < 1% indicates a very low probability of exploitation under current data. The flaw is not listed in CISA’s KEV catalog, but the ability to run arbitrary code remains available where management interfaces are reachable for authenticated users.
OpenCVE Enrichment