SB2025091778 - Multiple vulnerabilities in HPE Aruba Networking EdgeConnect SD-WAN Gateways



SB2025091778 - Multiple vulnerabilities in HPE Aruba Networking EdgeConnect SD-WAN Gateways

Published: September 17, 2025

Security Bulletin ID SB2025091778
Severity
High
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 11% Medium 44% Low 44%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 secuirty vulnerabilities.


1) OS Command Injection (CVE-ID: CVE-2025-37123)

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the command-line interface. A remote user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


2) Improper access control (CVE-ID: CVE-2025-37124)

The vulnerability allows a remote attacker to bypass firewall protections.

The vulnerability exists due to improper access restrictions. A remote attacker can route potentially harmful traffic through the internal network and access or disrupt the services.


3) Improper access control (CVE-ID: CVE-2025-37125)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in HPE Aruba Networking EdgeConnect OS (ECOS). A remote attacker can bypass firewall protections and gain access to sensitive information.


4) OS Command Injection (CVE-ID: CVE-2025-37126)

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


5) Cryptographic issues (CVE-ID: CVE-2025-37127)

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to an error in the cryptographic logic. A remote administrator can perform replay attack and execute arbitrary commands on the system.


6) Improper access control (CVE-ID: CVE-2025-37128)

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote user can terminate arbitrary running processes and perform a denial of service (DoS) attack.


7) OS Command Injection (CVE-ID: CVE-2025-37129)

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in Scripts feature. A remote administrator can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


8) Information disclosure (CVE-ID: CVE-2025-37130)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in the command-line interface. A remote user can read sensitive data from the underlying file system.


9) Information disclosure (CVE-ID: CVE-2025-37131)

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application in EdgeConnect SD-WAN ECOS. A remote administrator can gain unauthorized access to sensitive information on the system.


Remediation

Install update from vendor's website.