CVE-2025-37130: Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN Gateway
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying file system.
Affected products
- Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN Gateway: from 9.5.0.0, up to and including 9.5.3.6; from 9.4.0.0, up to and including 9.4.3.7
Published 2025-09-16. Last modified 2026-06-17.