Authenticated Command Injection Vulnerability in HPE Networking Access Points
CVE-2025-37102

7.2HIGH

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
8 July 2025

What is CVE-2025-37102?

An authenticated command injection vulnerability has been identified in the command line interface of HPE Networking Instant On Access Points. This flaw allows an attacker with elevated privileges to execute arbitrary commands on the underlying operating system, potentially compromising system integrity and security. Due to its nature, the vulnerability highlights the critical need for timely updates and adherence to security best practices to mitigate risks associated with remote exploitation.

Affected Version(s)

HPE Networking Instant On 3.2.0.0 <= 3.2.0.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZZ from Ubisectech Sirius Team
.
CVE-2025-37102 : Authenticated Command Injection Vulnerability in HPE Networking Access Points