AI analysis
An API endpoint on HPE Networking Instant On access points is vulnerable to server-side request forgery that can lead to arbitrary command execution. An authenticated remote attacker who already has high privileges can trigger the flaw over the network with no user interaction. Successful exploitation runs commands as a privileged user on the access point operating system, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.2). The advisory data names HPE Networking Instant On APs but does not list specific firmware versions. No public proof-of-concept is known, and the issue is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Check HPE's security advisory for CVE-2026-76728 and install the patched Instant On firmware it names; no fixed version is given in the available data, so do not assume a range. Until then, limit management API access to trusted admin networks and accounts, and review who holds high-privilege credentials on these access points. Watch for unexpected privileged processes or outbound requests from the AP.
Affected
| HPE Networking Instant On access points | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.