CVE-2026-76724
9.6 CRITICALPublished 2026-09-29 · Updated 2026-09-29
AI risk analysis
- Summary
- A command injection vulnerability allows unauthenticated attackers to execute arbitrary commands as a privileged user, potentially leading to full system compromise.
- Exploitability
- Exploitation is relatively easy given the attacker only needs to send specially crafted packets. No specific preconditions are required.
- Blast radius
- If exploited, the attacker could gain full control over the underlying operating system, leading to severe data loss or system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Disable the affected CLI feature or restrict access to the CLI interface to prevent command injection attacks.
rceclicommand-injectionunauthenticated
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2023-54400PoC
- CRITICALCVE-2025-29296
- HIGHCVE-2025-51457
- CRITICALCVE-2026-101008PoC
- CRITICALCVE-2026-101187PoC
- CRITICALCVE-2026-101260PoC
- CRITICALCVE-2026-101261PoC
- CRITICALCVE-2026-101262PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.