CVE-2026-76683

Summary

Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Affected Software

VendorProductVersion RangeStatus
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.7.0.0 <= 9.7.0.0affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.6.0.0 <= 9.6.3.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.5.0.0 <= 9.5.8.1affected
Hewlett Packard Enterprise (HPE)EdgeConnect SD-WAN Gateways9.4.0.0 <= 9.4.8.2affected

Weaknesses

References