Summary
CVE-2026-76683 is a buffer overflow vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways (ECOS) that could allow an unauthenticated remote attacker to execute arbitrary commands on the underlying host. Exploitation requires certain preconditions outside the attacker’s control, which raises attack complexity but does not require any authentication or user interaction. HPE rates this vulnerability High severity (CVSS v3.1 base score 8.1) and disclosed it alongside a broader set of EdgeConnect SD-WAN Gateway/Orchestrator vulnerabilities in advisory HPESBNW05135.
Technical details
- Root cause: A buffer overflow condition exists in the API endpoint exposed by the EdgeConnect SD-WAN Gateway (ECOS) software.
- Trigger conditions: Exploitation depends on certain preconditions outside the attacker’s control being met, which is reflected in the CVSS vector’s High attack complexity (AC:H) rating.
- Attack vector: Network-based; no authentication (PR:N) or user interaction (UI:N) is required to attempt exploitation.
- Impact: Successful exploitation can allow an unauthenticated remote attacker to run arbitrary commands on the underlying host operating system, potentially leading to complete compromise of confidentiality, integrity, and availability of the affected gateway.
Affected software
- HPE Networking EdgeConnect SD-WAN Gateway (ECOS) 9.7.0.0 and earlier
- HPE Networking EdgeConnect SD-WAN Gateway (ECOS) 9.6.0.0 through 9.6.3.1
- HPE Networking EdgeConnect SD-WAN Gateway (ECOS) 9.5.0.0 through 9.5.8.1
- HPE Networking EdgeConnect SD-WAN Gateway (ECOS) 9.4.0.0 through 9.4.8.2
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade affected EdgeConnect SD-WAN Gateway (ECOS) deployments to a fixed release:
- 9.7.x → 9.7.1.0 or later
- 9.6.x → 9.6.4.0 or later
- 9.5.x → 9.5.9.0 or later
- 9.4.x → 9.4.9.0 or later
- Note: HPE requires that the associated SD-WAN Orchestrator software version be greater than or equal to the ECOS version running on any managed Gateway.
- If immediate patching is not possible: HPE recommends restricting CLI and web-based management interfaces to a dedicated Layer 2 segment/VLAN, and/or controlling access via firewall policies at Layer 3 and above, along with enabling accounting controls to track and log user activity and resource usage on management interfaces.

