CVE-2025-37183: Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37183?
CVE-2025-37183 is classified as a critical vulnerability due to the potential for remote authenticated SQL injection attacks.
How do I fix CVE-2025-37183?
To resolve CVE-2025-37183, apply the latest security patches provided by the vendor for the EdgeConnect SD-WAN Orchestrator.
Who is affected by CVE-2025-37183?
Organizations using the web-based management interface of EdgeConnect SD-WAN Orchestrator are vulnerable to CVE-2025-37183.
What systems are impacted by CVE-2025-37183?
CVE-2025-37183 affects the EdgeConnect SD-WAN Orchestrator's web-based management interface specifically.
What can an attacker do with CVE-2025-37183?
An attacker could exploit CVE-2025-37183 to perform SQL injection attacks, potentially compromising the database and its data.