Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Is ‘Baby Grok’ the Future of Kids’ AI? Elon Musk Launches New Chatbot

Iran-linked DCHSPY Android malware is equipped with a VPN app that spies against the rebels

China-linked hackers launch targeted spy campaigns on Africa’s IT infrastructure

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Hardcoded credentials found in HPE instant on the device allow administrator access
Identity

Hardcoded credentials found in HPE instant on the device allow administrator access

userBy userJuly 21, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 21, 2025Ravi LakshmananNetwork Security/Vulnerabilities

Hewlett-Packard Enterprise (HPE) has released a security update to address critical security flaws that affect the instantaneous access point where attackers can bypass authentication and gain administrative access to the sensitive system.

The vulnerability tracked as CVE-2025-37103 has a CVSS score of 9.8 out of a maximum of 10.0.

“Hardcoded login credentials were found on the HPE Networking Instant on the Access Point, allowing anyone who knows it to bypass normal device authentication,” the company said in its advisory.

“The successful exploitation allows remote attackers to gain administrative access to the system.”

Cybersecurity

Also patched by HPE is a command injection flaw authenticated to the HPE Networking Instant command line interface on the access point (CVE-2025-37102, CVSS score: 7.2). This is that remote attackers can exploit with advanced privileges to execute arbitrary commands on any operating system with advanced operating systems.

This also means that attackers can fashion CVE-2025-37103 and CVE-2025-37102 into the exploit chain, gaining administrative access and inject malicious commands into the command line interface of follow-on activity.

The company praised the ZZ of the Ubisectech Sirius team for discovering and reporting two issues. Both vulnerabilities were resolved in HPE Network Instant software version 3.2.1.0 or higher.

HPE also noted in its advisory that other devices, such as the HPE Networking Instant on the Switch, are not affected.

Although there is no evidence that any of the flaws are under aggressive exploitation, users are advised to apply updates as soon as possible to mitigate potential threats.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article3,500 websites that have been secretly hijacked to mine cryptography using stealth JavaScript and WebSocket tactics
Next Article Microsoft releases emergency patch for SharePoint RCE flaws exploited in an ongoing cyberattack
user
  • Website

Related Posts

Iran-linked DCHSPY Android malware is equipped with a VPN app that spies against the rebels

July 21, 2025

China-linked hackers launch targeted spy campaigns on Africa’s IT infrastructure

July 21, 2025

SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and More

July 21, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Is ‘Baby Grok’ the Future of Kids’ AI? Elon Musk Launches New Chatbot

Iran-linked DCHSPY Android malware is equipped with a VPN app that spies against the rebels

China-linked hackers launch targeted spy campaigns on Africa’s IT infrastructure

Anduril alumni raises a $24 million Series A to extract military logistics from the Excel spreadsheet era

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Is ‘Baby Grok’ the Future of Kids’ AI? Elon Musk Launches New Chatbot

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.