PT-2025-28659 · Hewlett Packard · Hpe Networking Instant On Access Points

Published

2025-07-08

·

Updated

2025-07-26

·

CVE-2025-37102

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HPE Networking Instant On Access Points (affected versions not specified)
Description An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. Successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user. This vulnerability enables malicious activities, including configuration changes, backdoor installations, and data interception through traffic monitoring.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09275
CVE-2025-37102

Affected Products

Hpe Networking Instant On Access Points