Description
A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: 4.5% Low
KEV: No
Impact: Remote Command Execution potentially leading to Denial of Service on EdgeConnect SD‑WAN Gateways
Action: Apply Patch
AI Analysis

Impact

The flaw is a command injection vulnerability (CWE‑77) in the web‑based management interface of HPE EdgeConnect SD‑WAN Gateways. An authenticated remote attacker with limited privileges can send specially crafted input that is not correctly sanitized, allowing the attacker to execute arbitrary system commands with elevated privileges or trigger a denial‑of‑service condition on the affected appliance.

Affected Systems

All Hewlett Packard Enterprise EdgeConnect SD‑WAN Gateways that expose the web‑based management interface may be affected. No specific product version information was supplied, so the vulnerability may affect any current or future release until patched.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5 and an EPSS estimate of 4%, indicating moderate severity but a relatively low probability of exploitation in the field. It is not listed in the CISA KEV catalog, suggesting no publicly demonstrated attacks yet. The likely attack vector is the HTTP or HTTPS management interface, where an authenticated attacker with a limited privileged account can inject malicious commands. If successful, the attacker could disrupt services or gain elevated privileges. Based on the description, it is inferred that the degree of privilege escalation depends on how the application isolates user input from system calls.

Generated by OpenCVE AI on September 22, 2026 at 20:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the appliance firmware to the latest version that includes the fix for the command injection vulnerability.
  • Restrict access to the web‑based management interface to trusted administrators, enforce strong role‑based permissions, and limit the IP ranges that can reach it.
  • Implement rigorous input validation and sanitization for all user inputs that influence system commands.

Generated by OpenCVE AI on September 22, 2026 at 20:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System
CPEs cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.7.0:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:edgeconnect_operating_system:9.7.0.0:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator
Hpe
Hpe edgeconnect Operating System

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Sun, 20 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways
Vendors & Products Hewlett Packard Enterprise (hpe)
Hewlett Packard Enterprise (hpe) edgeconnect Sd-wan Gateways

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary commands with elevated privileges or a denial-of-service condition on the affected appliance.
Title Authenticated Command Injection Vulnerability leads to Denial-of-Service in HPE Networking EdgeConnect SD-WAN Gateways
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hewlett Packard Enterprise (hpe) Edgeconnect Sd-wan Gateways
Hpe Edgeconnect Operating System
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-09-22T14:12:37.793Z

Reserved: 2026-08-19T16:12:09.681Z

Link: CVE-2026-76698

cve-icon Vulnrichment

Updated: 2026-09-22T14:12:30.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:17:54.283

Modified: 2026-09-28T13:52:39.447

Link: CVE-2026-76698

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:15:09Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')