A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe edgeconnect Sd-wan Gateway |
|
| Vendors & Products |
Hpe
Hpe edgeconnect Sd-wan Gateway |
Thu, 23 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-377 CWE-732 |
|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data. | |
| Title | Authenticated Path Traversal allows Unauthorized Access in Web Interface | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2026-07-23T13:29:55.282Z
Reserved: 2026-05-07T21:29:22.243Z
Link: CVE-2026-44878
Updated: 2026-07-23T13:28:05.526Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T21:12:38Z