Hewlett Packard Enterprise released security updates for HPE Networking Instant On Access Points to fix two vulnerabilities affecting firmware version 3.2.0.1 and earlier. The most severe issue, CVE-2025-37103, is a critical hard-coded credentials flaw with a CVSS score of 9.8 that could allow a remote attacker to gain administrative access to the device web interface. HPE documented the issues in security bulletin HPESBNW04894 and urged customers to update affected systems.
HPE also patched CVE-2025-37102, a high-severity vulnerability with a CVSS score of 7.2 that allows a remote authenticated attacker to inject arbitrary commands into the device console and execute commands on the underlying system. The company recommended immediate upgrades to firmware version 3.2.1.0 or later to reduce the risk of unauthorized access and command execution on exposed access points.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
Hewlett Packard Enterprise released security updates for HPE Networking Instant On Access Point firmware to address two vulnerabilities affecting version 3.2.0.1 and earlier. The flaws include CVE-2025-37103, a critical hard-coded credentials issue, and CVE-2025-37102, a high-severity command injection issue; HPE recommended upgrading to firmware version 3.2.1.0 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.