Remote Process Termination Vulnerability in HPE Aruba Networking EdgeConnect SD-WAN Gateways
CVE-2025-37128
What is CVE-2025-37128?
A significant security flaw exists in the web API of HPE Aruba Networking EdgeConnect SD-WAN Gateways, which could allow an authenticated remote attacker to terminate any running process. This exploitation could lead to significant disruption in system operations, potentially causing the system to enter an unstable state that may affect network performance and reliability. Organizations using affected versions should prioritize patching to safeguard their environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HPE Aruba Networking EdgeConnect SD-WAN Gateway 9.5.0.0 <= 9.5.3.6
HPE Aruba Networking EdgeConnect SD-WAN Gateway 9.5.0.0 <= 9.5.3.6
HPE Aruba Networking EdgeConnect SD-WAN Gateway 9.4.0.0 <= 9.4.3.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
