T

Threats

HPE Networking Instant On Multiple Critical Vulnerabilities

Overview

HPE has disclosed five critical vulnerabilities affecting HPE Networking Instant On access points, including buffer overflows, command injection, an uncontrolled format string flaw and an authentication-control bypass.

The vulnerabilities could allow unauthenticated remote or adjacent-network attackers to execute arbitrary code or commands with elevated privileges, cause denial of service, or bypass security controls. Organisations should confirm affected models and firmware versions with HPE and prioritise vendor-directed updates.

Vulnerability Breakdown

CVE-2026-76721 - Buffer overflow

  • Severity: Critical

  • CVSS: 9.8

  • Description: A buffer overflow in an affected HPE Networking Instant On interface may allow an unauthenticated remote attacker to run arbitrary code on the underlying host.

  • Impact: Arbitrary code execution as a privileged user on the underlying operating system.

  • Conditions: Unauthenticated remote access to the affected interface.

CVE-2026-76722 - Uncontrolled format string

  • Severity: Critical

  • CVSS: 9.8

  • Description: An uncontrolled format string flaw in an affected Instant On AP interface may let an unauthenticated remote attacker run arbitrary commands on the underlying host.

  • Impact: Denial of service or potential remote code execution.

  • Conditions: Unauthenticated remote access to the affected interface.

CVE-2026-76723 - Buffer overflow

  • Severity: Critical

  • CVSS: 9.6

  • Description: A buffer overflow in an affected Instant On AP interface may allow an unauthenticated adjacent attacker to execute commands on the underlying operating system.

  • Impact: Remote code execution.

  • Conditions: Unauthenticated access from an adjacent network.

CVE-2026-76724 - Command injection

  • Severity: Critical

  • CVSS: 9.6

  • Description: A command injection flaw in the CLI of affected Instant On APs may be triggered by specially crafted packets from an unauthenticated adjacent attacker.

  • Impact: Arbitrary commands as a privileged user on the underlying operating system.

  • Conditions: Unauthenticated access from an adjacent network.

CVE-2026-76725 - Authentication-control bypass

  • Severity: Critical

  • CVSS: 9.6

  • Description: A vulnerability in an affected Instant On AP management protocol may allow an unauthenticated adjacent attacker to circumvent existing authentication controls.

  • Impact: A complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.

  • Conditions: Unauthenticated access from an adjacent network.

Mitigation

  • Confirm affected AP models and firmware against HPE's advisory, then install the version HPE identifies as fixed.

  • Until the fixed version is verified and applied, limit exposure of AP management interfaces and adjacent network access to trusted administration paths. This is interim defensive guidance, not a confirmed HPE workaround.

Summary for IT Teams

  • Products: HPE Networking Instant On APs

  • Threat level: Critical, CVSS up to 9.8

  • Action required: Verify the affected models and exact fixed firmware with HPE. Prioritise vendor-directed updates. Restrict management access while confirming exposure.

Reference

Need Help?

Contact Secure ISS on 1300 769 460 or email the Secure ISS team for assistance assessing exposure and remediation.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.