HPE Product Security Update Advisory
Overview
We have released security updates to fix vulnerabilities in HPE products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-37102, CVE-2025-37103
HPE Networking Instant On: 3.2.0.1 and earlier
Resolved Vulnerabilities
Command injection vulnerability in HPE Networking Instant On (CVE-2025-37102)
Hardcoded Credential Vulnerability in HPE Networking Instant On (CVE-2025-37103)
Vulnerability Patches
Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-37102, CVE-2025-37103
HPE Networking Instant On: 3.2.1.0 and later
References
[1] HPESBNW04894 rev.1 – HPE Networking Instant On Access Points, Multiple Vulnerabilities
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us&docLocale=en_US