PT-2025-38091 · Vmware · Edgeconnect Sd-Wan Ecos

Ncc Group

·

Published

2025-09-16

·

Updated

2025-09-17

·

CVE-2025-37131

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions EdgeConnect SD-WAN ECOS (affected versions not specified)
Description A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. This could lead to exposure and exfiltration of sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-12607
CVE-2025-37131

Affected Products

Edgeconnect Sd-Wan Ecos