CVE-2024-22246: VMware SD-WAN Edge

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router.

Affected products

  • VMware SD-WAN Edge: from 4.5, before 4.6 (fixed in 4.6); from 5, before 6 (fixed in 6)

Published 2024-04-02. Last modified 2026-06-17.