CVE-2025-37131: Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN Gateway

Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.

Affected products

  • Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN Gateway: from 9.5.0.0, up to and including 9.5.3.6; from 9.4.0.0, up to and including 9.4.3.7

Published 2025-09-16. Last modified 2026-06-17.