HPE Telecom Services Activator Vulnerability Allows Attackers to Bypass Access Restrictions

HPE Telecom Services Activator Vulnerability Allows Attackers to Bypass Access Restrictions

By Abinaya
Publication Date: 2026-02-23 12:38:00

HPE Telco Service Trigger Vulnerability

The security bulletin published on February 19, 2026 addresses a remote flaw in HPE Telco Service Activator that could allow attackers to bypass access restrictions.

According to HPE, the problem arises from the Undertow HTTP server core used by the product.

The failure is a bad input validation condition where the server cannot correctly validate the Host header in incoming HTTP requests.

In real-world deployments, many applications and gateways rely on the Host header to enforce allow lists, route requests, or apply security rules.

CVE IDcvssProductComponentVulnerability typeattack vectorImpactAffected versions
CVE-2025-125439.6 (Critical)HPE Telecom Services EnablerUndertow HTTP Server (core)Incorrect host header validationRemote (HTTP request)Access restriction bypass, possible unauthorized accessVersions prior to 10.5.0

When that header can be abused, an attacker can achieve the functionality…