Skip to content

Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS): command injection

High7.2CVE-2026-44879 · Published Jul 21, 2026 · updated Jul 23, 2026

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Affected versions

PackageAffectedFixed in
EdgeConnect SD-WAN Gateway (ECOS)
Product
>= 9.4.0.0, <= 9.4.4.0No fix yet
>= 9.5.0.0, <= 9.5.4.0No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-77

More Hewlett Packard Enterprise advisories

All Hewlett Packard Enterprise
Advisory
Hewlett Packard Enterprise EdgeConnect: information disclosure
Critical9.8Aug 4
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway: insecure permissions
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: buffer overflow
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: path traversal
High7.2Jul 21
Hewlett Packard Enterprise AOS-CX: buffer overflow
High8.8Jul 21
Hewlett Packard Enterprise HPE Networking Instant On: information disclosure
Medium6.5Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.