{"id":"CVE-2026-76724","published":"2026-09-29T20:17:24.453","lastModified":"2026-09-29T21:39:02.570","description":"A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"A command injection vulnerability allows unauthenticated attackers to execute arbitrary commands as a privileged user, potentially leading to full system compromise.","exploitability":"Exploitation is relatively easy given the attacker only needs to send specially crafted packets. No specific preconditions are required.","blast_radius":"If exploited, the attacker could gain full control over the underlying operating system, leading to severe data loss or system compromise.","remediation":"Disable the affected CLI feature or restrict access to the CLI interface to prevent command injection attacks.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","cli","command-injection","unauthenticated"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:57:19.468Z"}}