CVE-2025-37184General(arubanetworks / edgeconnect_sd-wan_orchestrator)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch arubanetworks edgeconnect_sd-wan_orchestrator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • edgeconnect_sd-wan_orchestrator

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
edgeconnect_sd-wan_orchestrator

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-22: 2Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 206-22
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • dbugs@ptdbugs
    General

    Sale of a 1‑day exploit in HPE Aruba Networking EdgeConnect SD‑WAN Orchestrator (CVE‑2025‑37184 -> (https://nvd.nist.gov/vuln/detail/CVE-2025-37184)) PT ID: PT-2026-2914 For informational purposes only. According to the seller, the exploit enables creation of an administrative account without MFA and grants full control over the system. Vulnerability type: authentication bypass Affected OS versions: • 9.2.0–9.2.10 • 9.3.0–9.3.5 • 9.4.0–9.4.2 • 9.5.0–9.5.5 • 9.6.0 Privileges obtained: admin #dbugs_darkweb

    Post summary

    The post announces the sale of a 1‑day exploit for HPE Aruba Networking EdgeConnect SD‑WAN that enables creation of an administrative account without MFA, but provides no patch, exploit code, or evidence of active use in the wild.

    0201962.1K
    3.0K followersView on X
  • CyberX@CyberXlx9q
    General

    ‼️𝗔𝗹𝗹𝗲𝗴𝗲𝗱 𝗦𝗮𝗹𝗲 𝗼𝗳 𝗛𝗣𝗘 𝗔𝗿𝘂𝗯𝗮 𝗖𝗩𝗘-𝟮𝟬𝟮𝟱-𝟯𝟳𝟭𝟴𝟰 𝗘𝘅𝗽𝗹𝗼𝗶𝘁 A threat actor claims to be selling an exploit targeting CVE-2025-37184, a critical vulnerability affecting HPE Aruba Networking EdgeConnect SD-WAN Orchestrator systems. According to the post, the alleged exploit enables unauthenticated attackers to bypass multi-factor authentication (MFA) protections and create administrator-level accounts on vulnerable systems. If authentic and successfully exploited, such a vulnerability could provide attackers with elevated access to affected network management environments, potentially enabling unauthorized administrative actions and broader compromise of enterprise infrastructure. Organizations using affected HPE Aruba products should ensure that available security updates, mitigations, and vendor guidance are reviewed and applied where appropriate. The functionality, effectiveness, and availability of the advertised exploit have not been independently verified. #CyberSecurity #HPE #Aruba #CVE202537184 #Vulnerability #ThreatIntel #NetworkSecurity

    Post summary

    The post reports a threat actor selling an exploit for CVE‑2025‑37184, enabling unauthenticated MFA bypass and admin account creation; no PoC or verified exploit is disclosed, but patching is recommended.

    00010254
    261 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apparubanetworksedgeconnect_sd-wan_orchestrator---
Apparubanetworksedgeconnect_sd-wan_orchestrator9.6.0--

Explore more