Hewlett Packard Enterprise EdgeConnect SD-WAN是美国Hewlett Packard Enterprise公司的一款支持软件定义广域网组网的企业级路由器。 Hewlett Packard Enterprise EdgeConnect SD-WAN 9.7.0版本、9.6.0版本至9.6.3版本、9.5.0版本至9.5.8版本和9.4.0版本至9.4.10版本存在安全漏洞,该漏洞源于API存在权限提升漏洞,可能导致远程低权限认证用户提升至管理员权限,造成系统完全被破
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.7.0≤ 9.7.0 |
affected |
9.6.0≤ 9.6.3 |
affected | ||
9.5.0≤ 9.5.8 |
affected | ||
9.4.0≤ 9.4.10 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Gateways | 9.7.0 ~ 9.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76670 | 9.9 CRITICAL | Authorization Bypass Leading to Privilege Escalation in EdgeConnect SD-WAN Orchestrator |
| CVE-2026-76672 | 9.9 CRITICAL | Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orches |
| CVE-2026-76673 | 9.8 CRITICAL | Authentication Bypass Vulnerabilities in API of EdgeConnect SD-WAN Orchestrator |
| CVE-2026-76674 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Netwo |
| CVE-2026-76675 | 9.1 CRITICAL | Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect |
| CVE-2026-76677 | 8.8 HIGH | Authorization Bypass Leading to Privilege Escalation in HPE Networking EdgeConnect SD-WAN |
| CVE-2026-76678 | 8.8 HIGH | Authenticated Command Injection Vulnerability leads to Remote Code Execution in EdgeConnec |
| CVE-2026-76676 | 8.8 HIGH | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in EdgeConne |
| CVE-2026-76679 | 8.6 HIGH | Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gat |
| CVE-2026-76681 | 8.5 HIGH | Authenticated Information Disclosure Vulnerability in HPE Networking EdgeConnect SD-WAN Or |
| CVE-2026-76680 | 8.5 HIGH | Authenticated Server-Side Request Forgery Vulnerabilities Leading to Information Disclosur |
| CVE-2026-76682 | 8.2 HIGH | Unauthenticated Denial-of-Service Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gat |
| CVE-2026-76684 | 8.1 HIGH | Authentication Bypass Vulnerabilities in HPE Networking EdgeConnect SD-WAN Orchestrator AP |
| CVE-2026-76685 | 8.1 HIGH | Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of- |
| CVE-2026-76683 | 8.1 HIGH | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Netwo |
| CVE-2026-76686 | 7.5 HIGH | Unauthenticated Denial-of-Service (DoS) Vulnerability leads to Service Disruption in HPE N |
| CVE-2026-76687 | 7.5 HIGH | Authenticated Arbitrary File Write Leading to Remote Code Execution in EdgeConnect SD-WAN |
| CVE-2026-76688 | 7.5 HIGH | Authentication Bypass Vulnerabilities in the Web-Based Management Interface of EdgeConnect |
| CVE-2026-76689 | 7.2 HIGH | Authenticated Buffer Overflow Vulnerability leads to Remote Code Execution or Denial-of-Se |
| CVE-2026-76690 | 7.2 HIGH | Authenticated Remote Code Execution Vulnerability in HPE Networking EdgeConnect SD-WAN Gat |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet