Command Injection Vulnerability in HPE Networking Instant ON APs
CVE-2026-76724
9.6CRITICAL
What is CVE-2026-76724?
A command injection vulnerability in the command-line interface (CLI) of HPE Networking Instant ON Access Points allows an unauthenticated attacker within proximity to execute arbitrary commands. By sending specially crafted packets, an attacker may gain unauthorized access and control over the underlying operating system, leading to potential data breaches and exploitation of network resources. Proper security measures and patching are critical to mitigate these risks.
Affected Version(s)
Instant ON 0.0.0.0 <= 3.4.1.0
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Internal security research (HPE Networking).
