Warning: Critical vulnerability (CVE-2025-37103) affects HPE Networking Instant On Access Points, allowing remote attackers to gain full administrative access, Patch Immediately!
ID: 4839276a-83eb-593b-8bdc-df1b28dbab89
STIX ID: report--4839276a-83eb-593b-8bdc-df1b28dbab89
Threat Score
HPE (Aruba) Instant On Access Points running versions ≤ 3.2.0.1 contain a critical hard-coded credential vulnerability (CVE-2025-37103, CVSS 9.8) that permits remote unauthenticated attackers to gain full administrative access, potentially enabling reconfiguration, traffic interception, malicious firmware installation, and lateral movement; organizations are advised to apply vendor updates immediately and increase monitoring, though there is currently no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
