CVE-2026-44879

Summary

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateway (ECOS)9.4.0.0 <= 9.4.4.0affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateway (ECOS)9.5.0.0 <= 9.5.4.0affected

Weaknesses

References