CVE-2025-37130: Unrestricted Binary allows File Enumeration in Underlying Operating System
A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated attacker to read arbitrary files within the system. Successful exploitation could allow an attacker to read sensitive data from the underlying file system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37130?
CVE-2025-37130 has a high severity rating due to the potential for unauthorized access to sensitive system files.
How do I fix CVE-2025-37130?
To fix CVE-2025-37130, apply the latest security updates and patches provided by the vendor for EdgeConnect SD-WAN.
Who is affected by CVE-2025-37130?
CVE-2025-37130 affects systems running EdgeConnect SD-WAN that utilize its command-line interface.
What type of data can be accessed via CVE-2025-37130?
CVE-2025-37130 allows an authenticated attacker to read arbitrary files, potentially exposing sensitive data.
What is the exploitation method for CVE-2025-37130?
Successful exploitation of CVE-2025-37130 requires authenticated access to the EdgeConnect SD-WAN command-line interface.