CVE-2026-76729: fallo de gravedad media en Hewlett Packard Enterprise (HPE) Instant ON
Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.6epss 0.4%
probabilidad de explotación
0.4%top 65% de las CVE
explotación observada
noninguna fuente lo reporta
A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Hewlett Packard Enterprise (HPE) · Instant ONCVEs relacionadas — Hewlett Packard Enterprise (HPE) Instant ON
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-76724CRITICALUnauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI ProtocolEPSS 1.0%CVE-2026-76727HIGHAuthenticated Command Injection Vulnerabilities in HPE Networking Instant ONEPSS 1.0%CVE-2026-76721CRITICALUnauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APsEPSS 0.6%CVE-2026-76722CRITICALUncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APsEPSS 0.5%CVE-2026-76728HIGHAuthenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APsEPSS 0.5%CVE-2026-76726HIGHAuthentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API EndpointEPSS 0.4%