CVE-2025-37128 MEDIUM

CVE-2025-37128: Authenticated Arbitrary Process Termination allows potential System Disruption in ECOS

Vendor Hewlett Packard Enterprise (Hpe)
Product HPE Aruba Networking EdgeConnect SD-WAN Gateway
Published September 16, 2025
Last update September 17, 2025

CVSS base score

6.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

A vulnerability in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to terminate arbitrary running processes. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.

Key dates

02Disclosure timeline

September 16, 2025 CVE published
September 17, 2025 Record updated