← Back to search

CVE-2026-76724

9.6 CRITICAL

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
A command injection vulnerability allows unauthenticated attackers to execute arbitrary commands as a privileged user, potentially leading to full system compromise.
Exploitability
Exploitation is relatively easy given the attacker only needs to send specially crafted packets. No specific preconditions are required.
Blast radius
If exploited, the attacker could gain full control over the underlying operating system, leading to severe data loss or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected CLI feature or restrict access to the CLI interface to prevent command injection attacks.
rceclicommand-injectionunauthenticated

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.