CVE-2026-76675
largeAuthenticated Command Injection in HPE Aruba EdgeConnect SD-WAN Gateways
A command injection vulnerability exists in the command line interface (CLI) of HPE Aruba Networking EdgeConnect SD-WAN Gateways, rated critical at CVSS 9.1. It is triggered when a remote attacker who already holds high-privilege (administrative) credentials submits crafted input to the gateway's CLI, allowing arbitrary commands to be executed on the underlying operating system. Successful exploitation gives the attacker full control of the appliance, compromising its confidentiality, integrity, and availability, and potentially the wider SD-WAN fabric it anchors. The flaw affects EdgeConnect SD-WAN Gateway deployments wherever the vulnerable CLI is reachable. No public proof of concept is known, the CVE is not in CISA's KEV catalog, and no in-the-wild exploitation has been reported, though the high privilege requirement and lack of user interaction make insider-threat and credential-reuse scenarios the primary risk paths.
What to do: Apply HPE's patched firmware as soon as the vendor advisory specifies fixed versions. Restrict CLI/SSH and management access to trusted administrative networks via ACLs or a dedicated management plane, rotate high-privilege admin credentials, and enforce role-based access so fewer accounts hold the high privileges this flaw requires. Review gateway logs for unexpected CLI command execution or configuration anomalies indicative of post-exploitation activity.
| HPE (Aruba Networking) EdgeConnect SD-WAN Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.