CVE-2025-37104: Hewlett Packard Enterprise HPE HPE Telco Service Orchestrator
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clients.
Affected products
- Hewlett Packard Enterprise HPE HPE Telco Service Orchestrator: before 5.2.1 (fixed in 5.2.1)
Published 2025-07-16. Last modified 2026-06-17.