CVE-2025-37131: Authenticated Arbitrary File Read allows Data Exposure in CLI Interface
A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37131?
CVE-2025-37131 is considered a high severity vulnerability due to the potential for exposed sensitive information.
How do I fix CVE-2025-37131?
To mitigate CVE-2025-37131, ensure EdgeConnect SD-WAN ECOS is updated to the latest version and review access controls.
Who is impacted by CVE-2025-37131?
CVE-2025-37131 affects organizations using EdgeConnect SD-WAN ECOS with systems that allow authenticated admin access.
What systems are vulnerable to CVE-2025-37131?
Systems running EdgeConnect SD-WAN ECOS that allow authenticated remote admin access are vulnerable to CVE-2025-37131.
What could happen if CVE-2025-37131 is exploited?
Exploitation of CVE-2025-37131 could lead to unauthorized access and potential exfiltration of sensitive system files.