Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4244 articles · 196959 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-44879
hewlett packard enterprise (hpe) · edgeconnect sd-wan gateway (ecos)

Authenticated Command Injection allows arbitrary command execution in CLI Interface

Description

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

Affected Products

VendorProductVersions
hewlett packard enterprise (hpe)edgeconnect sd-wan gateway (ecos)9.4.0.0, 9.5.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaedgeconnectcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05013en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories34d ago
[NEU] [mittel] Aruba EdgeConnect: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR34d ago
Multiples vulnérabilités dans les produits HPE Aruba Networking (22 juillet 2026)
→ No new info (linked only)
Tier C
VulDB34d ago
CVE-2026-44879 | HPE EdgeConnect SD-WAN Gateway up to 9.4.4.0/9.5.4.0 Command Line Interface command injection
→ No new info (linked only)
CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
PublishedJul 21, 2026
Last enriched34d agov2
Trending Score1
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63456
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Trending: 7
CRITICALCVE-2026-63455
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Trending: 7
MEDIUMCVE-2026-63457
CVE-2026-63457: A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
Trending: 4
HIGHCVE-2026-63454
Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX
Trending: 1
HIGHCVE-2026-63453
Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Updated: affectedVersions, severity, cweIds
Jul 21, 2026

Version History

v2
Last enriched 34d ago
v2Tier C34d ago

Updated affected versions to include 9.4.4.0 and 9.5.4.0, changed severity from HIGH to CRITICAL, and added CWE-78 (Command Injection).

affectedVersionsseveritycweIds
via VulDB
v134d ago

Initial creation