cbcvebase.

Hewlett Packard Enterprise Instant On vulnerabilities

20 known vulnerabilities affecting hewlett_packard_enterprise/instant_on.

Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH5MEDIUM7LOW3

Vulnerabilities

Page 1 of 1
CVE-2026-76722P2CRITICALCVSS 9.8≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76722 [CRITICAL] CWE-134 CVE-2026-76722: Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
nvd
CVE-2026-76721P2CRITICALCVSS 9.8≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76721 [CRITICAL] CWE-119 CVE-2026-76721: Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that cou Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
nvd
CVE-2026-76724P2CRITICALCVSS 9.6≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76724 [CRITICAL] CWE-77 CVE-2026-76724: A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that c A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-76725P2CRITICALCVSS 9.6≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76725 [CRITICAL] CWE-287 CVE-2026-76725: A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that c A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges
nvd
CVE-2026-76723P2CRITICALCVSS 9.6≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76723 [CRITICAL] CWE-120 CVE-2026-76723: Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS tha Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
nvd
CVE-2026-76726P2HIGHCVSS 8.1≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76726 [HIGH] CWE-287 CVE-2026-76726: An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to restricted networks.
nvd
CVE-2026-76727P3HIGHCVSS 7.2≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76727 [HIGH] CWE-77 CVE-2026-76727: Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-76728P3HIGHCVSS 7.2≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76728 [HIGH] CWE-918 CVE-2026-76728: A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated re A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2025-37165P3HIGHCVSS 7.5≥ 3.0.0.0, ≤ 3.3.1.02026-01-13
CVE-2025-37165 [HIGH] CWE-200 CVE-2025-37165: A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain net A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.
nvd
CVE-2026-76731P3MEDIUMCVSS 6.5≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76731 [MEDIUM] CWE-269 CVE-2026-76731: An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allo An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.
nvd
CVE-2025-37166P3HIGHCVSS 7.5≥ 3.0.0.0, ≤ 3.3.1.02026-01-13
CVE-2025-37166 [HIGH] CWE-770 CVE-2025-37166: A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this vulnerability to conduct a Denial-of-Service attack on a target network.
nvd
CVE-2026-76729P3MEDIUMCVSS 6.6≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76729 [MEDIUM] CWE-134 CVE-2026-76729: A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an au A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.
nvd
CVE-2026-76730P3MEDIUMCVSS 6.5≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76730 [MEDIUM] CWE-287 CVE-2026-76730: An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the
nvd
CVE-2026-76732P3MEDIUMCVSS 6.4≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76732 [MEDIUM] CWE-269 CVE-2026-76732: A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Network A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
nvd
CVE-2026-76734P4MEDIUMCVSS 4.8≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76734 [MEDIUM] CWE-119 CVE-2026-76734: A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.
nvd
CVE-2026-76733P4MEDIUMCVSS 4.9≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76733 [MEDIUM] CWE-400 CVE-2026-76733: A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.
nvd
CVE-2026-76735P4MEDIUMCVSS 4.1≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76735 [MEDIUM] CWE-200 CVE-2026-76735: A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Ne A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, on
nvd
CVE-2026-76736P4LOWCVSS 3.3≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76736 [LOW] CWE-119 CVE-2026-76736: A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
nvd
CVE-2026-76738P4LOWCVSS 2.7≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76738 [LOW] CWE-119 CVE-2026-76738: A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could a A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.
nvd
CVE-2026-76737P4LOWCVSS 3.0≥ 0.0.0.0, ≤ 3.4.1.02026-09-29
CVE-2026-76737 [LOW] CWE-22 CVE-2026-76737: An authenticated path traversal vulnerability exists in the command line interface of HPE Networking An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
nvd
Hewlett Packard Enterprise Instant On vulnerabilities | cvebase