HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
HPE patched 18 Instant On AP flaws, including unauthenticated remote code execution scored CVSS 9.8.
HPE advisory HPESBNW05150 covers 18 vulnerabilities in Networking Instant On access points running software 3.4.1.0 and earlier. CVE-2026-76721 and CVE-2026-76722, both CVSS 9.8, allow unauthenticated remote buffer-overflow code execution or format-string command execution. Three additional critical flaws scored 9.6 require adjacent-network access and can enable command injection, authentication bypass, or remote code execution. HPE said it was unaware of public exploit code as of September 29 and recommends upgrading to 3.4.2.0 or later, with automatic updates for eligible cloud-managed devices.
- Eighteen flaws affect Instant On AP software 3.4.1.0 and earlier.
- CVE-2026-76721 and CVE-2026-76722 are unauthenticated remote flaws scored CVSS 9.8.
- Three adjacent-network flaws scored 9.6 can lead to command execution or authentication bypass.
- HPE knew of no public exploit code as of the September 29 advisory.
- Upgrade to 3.4.2.0 or later; eligible devices can update via the cloud portal.
Vulnerabilities mentionedAll →
- CVE-2026-767219.8—Unauthenticated buffer overflow RCE in HPE Networking Instant Onpublished · Hewlett Packard Enterprise HPE Networking Instant On+2 related
- CVE-2026-767249.6—Unauthenticated command injection in HPE Instant On APspublished · HPE Networking Instant On access points+3 related
Full article550 words · extracted from gbhackers.com · click to collapse
HPE has released security updates for its Networking Instant On access points after identifying 18 vulnerabilities, including several critical flaws that could allow unauthenticated attackers to execute arbitrary code or commands with privileged operating-system access.
These vulnerabilities are detailed in advisory HPESBNW05150 rev. 1 and affect Instant On AP software versions 3.4.1.0 and earlier. HPE recommends that users upgrade to version 3.4.2.0 or later. Fixes will be automatically applied to eligible devices through the Instant On cloud management portal.
HPE Instant On AP Flaws
The most severe vulnerabilities are CVE-2026-76721 and CVE-2026-76722, both rated 9.8 out of 10 on the CVSS v3.1 scale. The first vulnerability is an unauthenticated remote buffer overflow flaw that could enable arbitrary code execution as a privileged user.
The second involves uncontrolled format-string vulnerabilities that could allow unauthenticated attackers to execute commands or trigger a denial-of-service condition.
Additionally, there are three other critical flaws, CVE-2026-76723, CVE-2026-76724, and CVE-2026-76725, each carrying a CVSS score of 9.6.
While these require access from adjacent networks rather than direct Internet connectivity, they could still facilitate arbitrary command execution, command injection through the PAPI-acquired command-line interface, or authentication bypass leading to elevated remote code execution.
The advisory also addresses CVE-2026-76726, an unauthenticated remote API authentication-bypass flaw with a CVSS score of 8.1. Under certain conditions beyond the attacker’s control, exploiting this vulnerability could allow unauthorized access to restricted networks.
CVE Details
| CVE | Severity | CVSS | Attack requirement | Impact |
|---|---|---|---|---|
| CVE-2026-76721 | Critical | 9.8 | Unauthenticated, remote | Buffer overflow; privileged RCE |
| CVE-2026-76722 | Critical | 9.8 | Unauthenticated, remote | Format string; command execution/DoS |
| CVE-2026-76723 | Critical | 9.6 | Unauthenticated, adjacent | Buffer overflow; arbitrary commands/RCE |
| CVE-2026-76724 | Critical | 9.6 | Unauthenticated, adjacent | PAPI CLI command injection |
| CVE-2026-76725 | Critical | 9.6 | Unauthenticated, adjacent | Management-protocol authentication bypass; potential RCE |
| CVE-2026-76726 | High | 8.1 | Unauthenticated, remote | API authentication bypass; unauthorized network access |
| CVE-2026-76727 | High | 7.2 | Authenticated, remote, high privilege | Command injection |
| CVE-2026-76728 | High | 7.2 | Authenticated, remote, high privilege | SSRF leading to privileged command execution |
| CVE-2026-76729 | Medium | 6.6 | Authenticated, remote, high privilege | Format string; memory corruption, DoS or RCE |
| CVE-2026-76730 | Medium | 6.5 | Unauthenticated, adjacent | PAPI authentication bypass; unauthorized traffic |
| CVE-2026-76731 | Medium | 6.5 | Unauthenticated, remote | Captive-portal authentication bypass |
| CVE-2026-76732 | Medium | 6.4 | Authenticated, local, high privilege | Local privilege escalation to root |
| CVE-2026-76733 | Medium | 4.9 | Authenticated, remote, admin | API denial of service |
| CVE-2026-76734 | Medium | 4.8 | Unauthenticated, remote | Memory-corruption denial of service |
| CVE-2026-76735 | Medium | 4.1 | Authenticated, local, high privilege | Sensitive-information disclosure |
| CVE-2026-76736 | Low | 3.3 | Authenticated, local, low privilege | Buffer-overflow denial of service |
| CVE-2026-76737 | Low | 3.0 | Authenticated, local, admin | Path traversal; limited file modification/DoS |
| CVE-2026-76738 | Low | 2.7 | Authenticated, remote, admin | API buffer-overflow denial of service |
Organizations should prioritize updating all supported Instant On APs to 3.4.2.0 or later. HPE also recommends isolating web-based management interfaces on a dedicated Layer 2 segment or VLAN, enforcing Layer 3-plus firewall policies, and maintaining activity and resource-use logging.
Deployments running end-of-maintenance releases should be treated as potentially exposed. HPE said it was unaware of public discussion or exploit code targeting these flaws as of the advisory’s September 29 release, but urged customers to patch given the breadth and potential impact of the vulnerabilities.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.