AI analysis
A command-injection flaw in the CLI of HPE Networking Instant On access points lets an unauthenticated attacker who is adjacent to the device send specially crafted packets and run arbitrary commands as a privileged user on the underlying operating system. The issue is rated critical (CVSS 3.1 9.6) with adjacent access, low complexity, no privileges, and no user interaction, and a changed scope with high impact to confidentiality, integrity, and availability. It affects HPE Networking Instant On APs; the provided data does not list specific models or version ranges. There is no CISA KEV listing and no public proof-of-concept is known, so exploitation in the wild is not indicated from this data.
What to do: Apply the HPE firmware fix for affected Instant On access points as soon as it is available for the models you run; the advisory data does not name a fixed version. Until then, keep the AP CLI off untrusted adjacent networks (management VLAN only, no exposure on guest or client segments) and alert on unexpected privileged command execution on the AP OS.
Affected
| HPE Networking Instant On access points | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.