Sale of a 1‑day exploit in HPE Aruba Networking EdgeConnect SD‑WAN Orchestrator (CVE‑2025‑37184)
Dark Web2026-06-22, 08:21
For informational purposes only
According to the seller, the exploit enables creation of an administrative account without MFA and grants full control over the system.
Vulnerability type: authentication bypass
Affected OS versions:
• 9.2.0–9.2.10
• 9.3.0–9.3.5
• 9.4.0–9.4.2
• 9.5.0–9.5.5
• 9.6.0
Privileges obtained: admin
Vulnerabilities
Researchers
Vendors
Products