CVE-2026-76683: Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require credentials or user interaction?
No. The vulnerability is reachable remotely without authentication and does not require user interaction.
What conditions must be present for an attacker to exploit this issue?
Exploitation depends on certain preconditions that are outside the attacker's control. The available information does not identify those preconditions.
What is the potential impact of successful exploitation?
An attacker could execute arbitrary commands on the gateway's underlying operating system, potentially resulting in complete system compromise.