
- HPE patched CVE-2025-37103 and CVE-2025-37102
- The former is a case of hardcoded credentials for an admin account
- The latter allows the execution of arbitrary commands as an admin
HPE has patched a critical-severity vulnerability in its Aruba Instant On Access Points which could have allowed threat actors to access the devices as an admin, change settings, deploy malware, and wreak havoc as they see fit.