{"id":"CVE-2026-76725","published":"2026-09-29T20:17:24.580","lastModified":"2026-09-29T21:39:02.570","description":"A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05150en_us&docLocale=en_US","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an unauthenticated attacker to bypass security controls and potentially execute remote code with elevated privileges, posing a significant risk to network security.","exploitability":"Exploitation is relatively straightforward given the unauthenticated nature and could be attempted by adjacent attackers.","blast_radius":"If exploited, the vulnerability could lead to complete control over the affected HPE Networking Instant ON APs, with potential for widespread damage.","remediation":"Upgrade to the latest firmware version 2.590 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","firmware"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:57:30.488Z"}}