← Back to search

CVE-2026-76725

9.6 CRITICAL

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
This vulnerability allows an unauthenticated attacker to bypass security controls and potentially execute remote code with elevated privileges, posing a significant risk to network security.
Exploitability
Exploitation is relatively straightforward given the unauthenticated nature and could be attempted by adjacent attackers.
Blast radius
If exploited, the vulnerability could lead to complete control over the affected HPE Networking Instant ON APs, with potential for widespread damage.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest firmware version 2.590 or later.
rceauth-bypassfirmware

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code execution with elevated privileges.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.