CVE-2025-37129: Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN Gateway

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures.

Affected products

  • Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN Gateway: from 9.5.0.0, up to and including 9.5.3.6; from 9.4.0.0, up to and including 9.4.3.7

Published 2025-09-16. Last modified 2026-06-17.