logo

Warning: Critical vulnerability (CVE-2025-37103) affects HPE Networking Instant On Access Points, allowing remote attackers to gain full administrative access, Patch Immediately!

ID: 4839276a-83eb-593b-8bdc-df1b28dbab89

STIX ID: report--4839276a-83eb-593b-8bdc-df1b28dbab89

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
85/100

Date Published: 2025-07-10

Date Updated: 2026-07-24

...
...

HPE (Aruba) Instant On Access Points running versions ≤ 3.2.0.1 contain a critical hard-coded credential vulnerability (CVE-2025-37103, CVSS 9.8) that permits remote unauthenticated attackers to gain full administrative access, potentially enabling reconfiguration, traffic interception, malicious firmware installation, and lateral movement; organizations are advised to apply vendor updates immediately and increase monitoring, though there is currently no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.