Researchers have discovered two high-risk security vulnerabilities (CVE-2025-37102 and CVE-2025-37103) in HPE's Networking Instant On wireless access points. The vulnerability types are
OS Command Injection and Use of Hard-coded Credentials, respectively. The former allows a remote attacker with administrative privileges to inject and execute arbitrary operating system commands on the device, while the latter allows an unauthenticated remote attacker to use fixed account credentials to log in to the system with administrator privileges. Please confirm and patch as soon as possible.