Hewlett-Packard Enterprise (HPE) warned of a critical authentication bypass vulnerability in its wireless networking device line designed for small enterprises.
HPE reported this month that “hardcoded login credentials were found in HPE Networking Instant On Access Points," allowing anyone with knowledge of it to bypass normal device authentication and gain administrative access to the system.
Tracked as CVE-2025-37103 and ranked as "critical," the vulnerability affects Aruba Instant On Access Points running firmware version 3.2.0.1 and below. It does not affect HPE’s Networking Instant On Switches.
HPE recommended last week that users upgrade to HPE Networking Instant On software version 3.2.1.0 and above.
No exploits of the flaw have yet been reported.
HPE also revealed a second, lesser vulnerability, tracked as CVE-2025-37102.
The authenticated command injection vulnerability is found in the command line interface of HPE Networking Instant On Access Points. The bug is similar to a command injection vulnerability that affected Aruba access points in November and was offered a patch in the same month.
HPE reported a successful exploit of the flaw could see a remote attacker with elevated privileges “execute arbitrary commands on the underlying operating system as a highly privileged user.”
No exploits of this flaw have been reported either, and in response, HPE recommended the same solution of upgrading to Networking Instant On software version 3.2.1.0 and above.
The cybersecurity issue follows recent news that HPE has reported denial-of-service (DOS) vulnerabilities affecting its servers, which is linked to an ongoing Intel processor issue. HPE reported the vulnerability in certain SimpliVity servers, with Intel processors at risk of being locally exploited.
Comments