7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.
Basic Information
ID
CVE-2025-37183
Source
hpe
Published
Jan 14, 2026 at 16:18
Modified
Jan 14, 2026 at 16:44
Affected Product
Vendor
Hewlett Packard Enterprise (HPE)
Product
EdgeConnect SD-WAN Orchestrator
Version
9.5.0
Affected Versions
Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator 9.5.0
Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator 9.4.0
Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator 9.4.0