Authenticated Command Injection Vulnerability in HPE Networking Access Points
CVE-2025-37102
7.2HIGH
What is CVE-2025-37102?
An authenticated command injection vulnerability has been identified in the command line interface of HPE Networking Instant On Access Points. This flaw allows an attacker with elevated privileges to execute arbitrary commands on the underlying operating system, potentially compromising system integrity and security. Due to its nature, the vulnerability highlights the critical need for timely updates and adherence to security best practices to mitigate risks associated with remote exploitation.
Affected Version(s)
HPE Networking Instant On 3.2.0.0 <= 3.2.0.1
News Articles
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
- đź“°
First article discovered by Cyber Press
Vulnerability published
Vulnerability Reserved
Credit
ZZ from Ubisectech Sirius Team