Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› HPE Aruba Instant On Hard-Coded Credentials 2025: How…
Breach analysis Incident: 8 Jul 2025

HPE Aruba Instant On Hard-Coded Credentials 2025: How CVE-2025-37103 Gave Anyone Admin Access to Access Points

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 6 min read
Category: NHI
On this page

In July 2025, Hewlett Packard Enterprise disclosed that its Aruba Instant On access points, compact Wi-Fi devices aimed at small and medium-sized businesses, contained hard-coded administrator credentials in their firmware. "Hardcoded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication," HPE's advisory said. "Successful exploitation could allow a remote attacker to gain administrative access to the system." Tracked as CVE-2025-37103 with a CVSS score of 9.8, the flaw affected firmware 3.2.0.1 and earlier. HPE also disclosed CVE-2025-37102, a command injection flaw in the device command line that requires admin access, so the two could be chained for full control. The fix is firmware 3.2.1.0 or later; there is no workaround. HPE said it was not aware of any exploitation. The flaw was reported by a researcher from the Ubisectech Sirius Team.

Key takeaways

  • Aruba Instant On access points running firmware 3.2.0.1 or earlier contained hard-coded admin credentials (CVE-2025-37103, CVSS 9.8).
  • Anyone who knew the credentials could bypass authentication and log in to the web interface as an administrator.
  • A second flaw, CVE-2025-37102, allowed command injection once an attacker had admin access.
  • Firmware 3.2.1.0 fixes both; HPE reported no known exploitation.
  • The identity lesson: a credential shipped in firmware is shared by every device and cannot be rotated by the owner, so it is a permanent back door until patched.

At a glance

OrganisationsHewlett Packard Enterprise (HPE Networking Instant On); businesses using Aruba Instant On access points
WhenCVE published 8 July 2025; reported widely from 20 July 2025
AttackerNone known. Found by a researcher from the Ubisectech Sirius Team
Entry pointHard-coded administrator credentials in the access point firmware
Identities abusedA built-in administrator credential shared by all affected devices
ImpactRemote administrative access possible on vulnerable devices; no exploitation reported
CategoryNHI. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach)

What happened

The CVE record for CVE-2025-37103 was published on 8 July 2025 with a CVSS v3.1 score of 9.8 (critical), covering HPE Networking Instant On access points up to firmware 3.2.0.1. BleepingComputer reported HPE's bulletin on 20 July, noting that "As the administrative credentials are hardcoded in the firmware, discovering them is trivial for knowledgeable actors." With admin access to the web interface, attackers "may change the access point's settings, reconfigure security, install backdoors, perform stealthy surveillance by capturing traffic, or even attempt lateral movement."

The same bulletin covered CVE-2025-37102, a high-severity authenticated command injection flaw in the device's command line interface. Because it needs admin access, it "can be chained with CVE-2025-37103," BleepingComputer explained, allowing attackers to run arbitrary commands for data exfiltration, disabling security and persistence. SOCRadar summarised the combination as "a full compromise scenario."

HPE advised upgrading to firmware 3.2.1.0 or later and said no workarounds exist. Instant On switches are not affected. "HPE Aruba Networking is not aware of any reports of exploitation of the two flaws," BleepingComputer reported.

Timeline

DateEvent
8 July 2025CVE-2025-37103 is published.
20 July 2025BleepingComputer reports HPE's warning.
21 July 2025SOCRadar publishes an analysis of the flaw.

How it happened: the identity attack path

  1. Credential in firmware. An administrator login was built into every affected device's firmware.
  2. Credential discoverable. Anyone analysing the firmware could find it.
  3. Authentication bypass. The credential grants admin access to the web interface without the owner's password.
  4. Command injection. With admin access, CVE-2025-37102 allows arbitrary commands.
  5. Network foothold. A compromised access point can capture traffic and support lateral movement.

Impact

  • Affected: Aruba Instant On access points on firmware 3.2.0.1 and earlier.
  • Potential: full administrative control, traffic capture, backdoors and lateral movement.
  • Exploitation: none reported by HPE.

What this means for NHI governance

Hard-coded credentials are non-human identities that nobody can govern. The device owner cannot see them, change them or turn them off, and every device running the same firmware shares them. Once one person extracts the credential, every unpatched device is open. Small business networking gear is often deployed once and not updated, which extends the window.

For buyers, this is a reason to include firmware update practices and credential design in vendor evaluation, and to keep an inventory of network devices so patches can be applied. For vendors, device credentials should be unique per device or set by the owner at setup. See our Device and IoT Identity Guide and Secrets Management Guide.

Recommendations

  • Update to firmware 3.2.1.0 or later. There is no workaround.
  • Inventory network devices. Know which access points and firmware versions you run. See the Device and IoT Identity Guide.
  • Restrict management interfaces. Do not expose device web interfaces to untrusted networks.
  • Reset admin credentials after patching. Use strong, unique passwords per device. See the Password Security Guide.
  • Ask vendors about embedded credentials. Make per-device credentials a purchasing requirement.

Frequently asked questions

What is CVE-2025-37103?

A critical vulnerability in HPE Aruba Instant On access points (firmware 3.2.0.1 and earlier): hard-coded admin credentials that let anyone who knows them bypass authentication and log in as administrator.

Has CVE-2025-37103 been exploited?

HPE said it was not aware of any exploitation at the time of disclosure.

How do I fix it?

Upgrade Aruba Instant On access points to firmware 3.2.1.0 or later. HPE says there is no workaround.

Salt Typhoon Telecom Intrusions 2025 · McHire Default Password Flaw 2025 · Device and IoT Identity Guide · Secrets Management Guide · Password Security Guide

How NHI Mgmt Group can help

Device credentials are among the least visible identities in a network. We help teams inventory devices, track embedded and default credentials and build patching into identity governance. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org