Command Injection Vulnerability in HPE Networking Instant ON APs
CVE-2026-76724

9.6CRITICAL

Key Information:

Vendor

HP (HP)

Vendor
CVE Published:
29 September 2026

What is CVE-2026-76724?

A command injection vulnerability in the command-line interface (CLI) of HPE Networking Instant ON Access Points allows an unauthenticated attacker within proximity to execute arbitrary commands. By sending specially crafted packets, an attacker may gain unauthorized access and control over the underlying operating system, leading to potential data breaches and exploitation of network resources. Proper security measures and patching are critical to mitigate these risks.

Affected Version(s)

Instant ON 0.0.0.0 <= 3.4.1.0

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Internal security research (HPE Networking).
.