PT-2026-2911 · Vmware · Edgeconnect Sd-Wan Orchestrator

Moonv

·

Published

2026-01-13

·

Updated

2026-01-14

·

CVE-2025-37181

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EdgeConnect SD-WAN Orchestrator (affected versions not specified)
Description The web-based management interface contains flaws that permit an authenticated remote attacker to conduct SQL injection attacks. Exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially resulting in unauthorized data access or manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00650
CVE-2025-37181

Affected Products

Edgeconnect Sd-Wan Orchestrator