CVE-2025-37129: Authenticated Remote Code Execution allows Exploit in Scripts Feature
A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37129?
CVE-2025-37129 is considered a high-severity vulnerability due to the potential for arbitrary command execution on the underlying operating system.
How do I fix CVE-2025-37129?
To mitigate CVE-2025-37129, ensure that you apply the latest security patches provided by EdgeConnect for the SD-WAN product.
Who is affected by CVE-2025-37129?
CVE-2025-37129 affects users of EdgeConnect SD-WAN with access to the command line interface.
What type of vulnerability is CVE-2025-37129?
CVE-2025-37129 is a command injection vulnerability that allows authenticated attackers to execute arbitrary commands.
Can CVE-2025-37129 be exploited remotely?
No, CVE-2025-37129 requires authentication, meaning an attacker must have valid credentials to exploit this vulnerability.