Sale of a 1‑day exploit in HPE Aruba Networking EdgeConnect SD‑WAN Orchestrator (CVE‑2025‑37184)

Dark Web2026-06-22, 08:21
For informational purposes only
According to the seller, the exploit enables creation of an administrative account without MFA and grants full control over the system.
Vulnerability type: authentication bypass Affected OS versions: • 9.2.0–9.2.10 • 9.3.0–9.3.5 • 9.4.0–9.4.2 • 9.5.0–9.5.5 • 9.6.0 Privileges obtained: admin
Vulnerabilities
9.8
CVE-2025-37184
Researchers
Nicholas Starke
Vendors
Hpe Aruba Networking
Products
Edgeconnect Sd-Wan Orchestrator