Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3435 articles · 210649 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-44879
hewlett packard enterprise (hpe) · edgeconnect sd-wan gateway (ecos)

Authenticated Command Injection allows arbitrary command execution in CLI Interface

Description

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Affected Products

VendorProductVersions
hewlett packard enterprise (hpe)edgeconnect sd-wan gateway (ecos)9.4.0.0, 9.5.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaedgeconnectcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05013en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories45d ago
[NEU] [mittel] Aruba EdgeConnect: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR46d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026)
→ No new info (linked only)
Tier C
VulDB46d ago
CVE-2026-44879 | HPE EdgeConnect SD-WAN Gateway up to 9.4.4.0/9.5.4.0 Command Line Interface command injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
PublishedJul 21, 2026
Last enriched46d agov2
Trending Score0
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-73750
Authenticated Buffer Overflow Vulnerabilities in AOS-CX API Endpoint Leads to Possible Code Execution
Trending: 37
HIGHCVE-2026-73773
Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX
Trending: 34
HIGHCVE-2026-73780
Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX
Trending: 30
HIGHCVE-2026-73776
Authenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CX
Trending: 30
HIGHCVE-2026-73779
Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX
Trending: 30

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions, severity, cweIds
Jul 21, 2026

Version History

v2
Last enriched 46d ago
v2Tier C46d ago

Updated affected versions to include 9.4.4.0 and 9.5.4.0, changed severity from HIGH to CRITICAL, and added CWE-78 (Command Injection).

affectedVersionsseveritycweIds
via VulDB
v146d ago

Initial creation