
Sale of a 1‑day exploit in HPE Aruba Networking EdgeConnect SD‑WAN Orchestrator (CVE‑2025‑37184 -> (https://nvd.nist.gov/vuln/detail/CVE-2025-37184)) PT ID: PT-2026-2914 For informational purposes only. According to the seller, the exploit enables creation of an administrative account without MFA and grants full control over the system. Vulnerability type: authentication bypass Affected OS versions: • 9.2.0–9.2.10 • 9.3.0–9.3.5 • 9.4.0–9.4.2 • 9.5.0–9.5.5 • 9.6.0 Privileges obtained: admin #dbugs_darkweb
Post summary
The post announces the sale of a 1‑day exploit for HPE Aruba Networking EdgeConnect SD‑WAN that enables creation of an administrative account without MFA, but provides no patch, exploit code, or evidence of active use in the wild.

