ZeroHour

CVE-2026-76691

moderate

Authenticated Buffer Overflow RCE in HPE EdgeConnect SD-WAN Gateway API

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways, allowing a remote attacker to execute arbitrary commands as a privileged user on the appliance's underlying operating system. Exploitation requires authentication with high privileges (per the CVSS vector PR:H), so the likely attacker profile is an attacker with stolen or compromised admin-level API credentials, or a malicious insider. Successful exploitation yields full control of the gateway OS, exposing routed traffic, VPN/SD-WAN overlays, and adjacent network segments. The flaw affects HPE Networking EdgeConnect SD-WAN Gateway appliances wherever the affected code is deployed; specific fixed and affected versions are not stated in the source data. There is no known public proof of concept and no indication of in-the-wild exploitation (not on the CISA KEV).

What to do: Apply HPE's patched firmware as specified in the vendor's security bulletin for this CVE, since the affected version range is only defined there. Restrict gateway API and management access to trusted administrative networks or VPN, rotate admin/API credentials, and enforce MFA where supported, since exploitation requires high privileges. Review gateway logs for unexpected privileged command execution or anomalous API activity originating from unfamiliar sources.

Affected
Hewlett Packard Enterprise (HPE) HPE Networking EdgeConnect SD-WAN Gateways
Estimated exposure
moderateestimated low tens of thousands of gateway appliances (thousands of enterprise SD-WAN deployments) — EdgeConnect (formerly Aruba EdgeConnect SD-WAN) is a major enterprise SD-WAN platform where customers typically deploy one or more internet-facing gateway appliances per branch or data center, but no public active-install or scan counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system.

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.