Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29665 | A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures. |
Wed, 17 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
ssvc
|
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks edgeconnect Enterprise Hp Hp arubaos |
|
| Vendors & Products |
Arubanetworks
Arubanetworks edgeconnect Enterprise Hp Hp arubaos |
Tue, 16 Sep 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploit built-in script execution capabilities. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system if the feature is enabled without proper security measures. | |
| Title | Authenticated Remote Code Execution allows Exploit in Scripts Feature | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-09-17T13:59:59.039Z
Reserved: 2025-04-16T01:28:25.367Z
Link: CVE-2025-37129
Updated: 2025-09-17T13:59:34.662Z
Status : Deferred
Published: 2025-09-16T23:15:32.773
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-37129
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:52:04Z
EUVD