HPE warns hardcoded passwords in Aruba hardware could pose a major security risk




  • HPE patched CVE-2025-37103 and CVE-2025-37102
  • The former is a case of hardcoded credentials for an admin account
  • The latter allows the execution of arbitrary commands as an admin

HPE has patched a critical-severity vulnerability in its Aruba Instant On Access Points which could have allowed threat actors to access the devices as an admin, change settings, deploy malware, and wreak havoc as they see fit.

Aruba Instant On Access Points are Wi-Fi devices designed for small businesses. They are advertised as easy-to-deploy devices offering fast, secure, and reliable wireless connectivity.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *