CVE-2026-76683
moderateUnauthenticated API Buffer Overflow RCE in HPE EdgeConnect SD-WAN Gateways
Buffer overflow vulnerabilities in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to execute arbitrary commands on the appliance's underlying operating system, leading to complete system compromise. Exploitation is triggered by sending crafted requests to the vulnerable API endpoint, but it depends on certain preconditions outside the attacker's control, which is reflected in the high attack-complexity rating (CVSS 3.1: 8.1, AV:N/AC:H/PR:N/UI:N). Any organization running EdgeConnect SD-WAN gateways (formerly Aruba/Silver Peak EdgeConnect) with the management/API interface reachable is potentially affected. There is no known public proof of concept, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported to date.
What to do: Apply the firmware update specified in HPE's security bulletin for EdgeConnect SD-WAN gateways as soon as the fixed release is identified for your deployment. Restrict gateway management/API access to trusted internal networks or VPN and confirm the API endpoint is not exposed to the internet. Review gateway logs for unexpected command execution or configuration anomalies that could indicate an exploitation attempt.
| Hewlett Packard Enterprise (HPE) Networking EdgeConnect SD-WAN Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.