Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 20 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator |
|
| CPEs | cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.6.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Arubanetworks
Arubanetworks edgeconnect Sd-wan Orchestrator |
Thu, 15 Jan 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe edgeconnect Sd-wan Orchestrator |
|
| Vendors & Products |
Hpe
Hpe edgeconnect Sd-wan Orchestrator |
Wed, 14 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
ssvc
|
Wed, 14 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface and thereby make unauthorized arbitrary configuration changes to the host. | |
| Title | Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-01-14T16:47:13.535Z
Reserved: 2025-04-16T01:28:25.381Z
Link: CVE-2025-37185
Updated: 2026-01-14T16:47:10.609Z
Status : Analyzed
Published: 2026-01-14T17:16:06.437
Modified: 2026-01-20T18:14:09.340
Link: CVE-2025-37185
No data.
OpenCVE Enrichment
Updated: 2026-01-15T08:03:36Z