Impact
The flaw permits an attacker who can authenticate to the HPE EdgeConnect gateway to send a specially crafted input that causes the device to execute arbitrary operating‑system commands as root, providing full system control. The vulnerability is characteristic of command injection, allowing the attacker to run whichever commands they choose with the privileges of the gateway’s most privileged account. The CVSS base score of 7.2 reflects the significant impact and required authentication for exploitation.
Affected Systems
All Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways are listed as affected. The advisory does not specify firmware or hardware revisions, indicating that any deployed gateway at the time should be considered vulnerable. Administrators should identify which gateway models are in use and determine if they run the impacted image.
Risk and Exploitability
Exploitation requires valid credentials; once authenticated, the attacker may exploit the input processing component to gain root privileges. While no EPSS score is published and the flaw is not in CISA’s KEV catalog, the possibility of remote code execution remains high in environments where gateway management interfaces are reachable for authenticated users. Successful exploitation would give the attacker complete control over the gateway’s operations and the data passing through it.
OpenCVE Enrichment