CVE-2025-37103: Hardcoded Credential Exposure Allows Unauthorized Access in Web Interface
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37103?
CVE-2025-37103 has a high severity due to the presence of hard-coded login credentials that allow unauthorized administrative access.
How do I fix CVE-2025-37103?
To fix CVE-2025-37103, users should update their HPE Networking Instant On Access Points to the latest firmware version that eliminates the hard-coded credentials.
Who is affected by CVE-2025-37103?
CVE-2025-37103 affects all models of HPE Networking Instant On Access Points that utilize the vulnerable hard-coded credentials.
What are the potential impacts of exploiting CVE-2025-37103?
Exploitation of CVE-2025-37103 could lead to unauthorized access, enabling attackers to control network settings and sensitive data.
Is there a workaround for CVE-2025-37103?
Currently, there are no official workarounds for CVE-2025-37103 other than applying the necessary firmware update.