Skip to content
VulniPulse

HPE Aruba Networking EdgeConnect SD-WAN Vulnerabilities & Security Advisories

17 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as EdgeConnect SD-WAN, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 9 high, 7 medium.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba EdgeConnect SD-WAN advisories

Critical9.8Aruba

Critical [CVE-2026-63456] Authentication bypass via spoofed HTTP headers Orchestrator REST API

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. Affected product named by the advisory: EdgeConnect SD-WAN Orchestrator.

CVE-2026-63456
EdgeConnect SD-WANWireless & Controllers
Aug 4, 2026
High7.2Aruba

High [CVE-2025-37183] Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

CVE-2025-37183
EdgeConnect SD-WAN
Jan 14, 2026
Medium5.5Aruba

Medium [CVE-2025-37185] Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface and thereby make unauthorized arbitrary configuration changes to the host.

CVE-2025-37185
EdgeConnect SD-WAN
Jan 14, 2026
High7.2Aruba

High [CVE-2025-37127] vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access and control over the affected systems.

CVE-2025-37127
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2025-37126] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.

CVE-2025-37126
EdgeConnect SD-WAN
Sep 16, 2025
High7.5Aruba

High [CVE-2025-37125] EdgeConnect: broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS).

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

CVE-2025-37125
EdgeConnect SD-WAN
Sep 16, 2025
High8.8Aruba

High [CVE-2025-37123] vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVE-2025-37123
EdgeConnect SD-WAN
Sep 16, 2025
Medium4.9Aruba

Medium [CVE-2025-37131] vulnerability in EdgeConnect SD-WAN ECOS could

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.

CVE-2025-37131
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.5Aruba

Medium [CVE-2025-37130] vulnerability in the command-line interface of EdgeConnect SD-WAN could

A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying file system.

CVE-2025-37130
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.7Aruba

Medium [CVE-2025-37129] vulnerable feature in the command line interface of EdgeConnect SD-WAN could

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures.

CVE-2025-37129
EdgeConnect SD-WAN
Sep 16, 2025
Medium6.8Aruba

Medium [CVE-2025-37128] vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.

CVE-2025-37128
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2024-41135] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise

CVE-2024-41135
EdgeConnect SD-WAN
Jul 24, 2024
High7.2Aruba

High [CVE-2024-33519] vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could

A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-33519
EdgeConnect SD-WAN
Jul 24, 2024
High8.1Aruba

High [CVE-2024-41914] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVE-2024-41914
EdgeConnect SD-WAN
Jul 24, 2024
High7.2Aruba

High [CVE-2024-22443] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-22443
EdgeConnect SD-WAN
Jul 24, 2024
Medium6.8Aruba

Medium [CVE-2024-41136] authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line…

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2024-41136
EdgeConnect SD-WAN
Jul 24, 2024
Medium6.1Aruba

Medium [CVE-2024-22444] vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.

CVE-2024-22444
EdgeConnect SD-WAN
Jul 24, 2024

← All Aruba advisories