CVE-2025-37103 PUBLISHED

Hardcoded Credential Exposure Allows Unauthorized Access in Web Interface

Assigner: hpe
Reserved: 16.04.2025 Published: 08.07.2025 Updated: 08.07.2025

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product HPE Networking Instant On
Versions Default: affected
  • affected from 3.2.0.0 to 3.2.0.1 (incl.)

Credits

  • ZZ from Ubisectech Sirius Team reporter

References