HPE Aruba Vulnerabilities Enables Unauthorized Access to Sensitive Information
Hewlett Packard Enterprise (HPE) has identified four high-severity vulnerabilities in Aruba Networking Instant On devices. These vulnerabilities could allow unauthorized access to sensitive network information and potentially disrupt operations.
Hewlett Packard Enterprise (HPE) has identified four high-severity vulnerabilities in Aruba Networking Instant On devices. These vulnerabilities could allow unauthorized access to sensitive network information and potentially disrupt operations.
Vulnerability Details and Risk Assessment
The vulnerabilities, identified as CVE-2025-37165, CVE-2025-37166, CVE-2023-52340, and CVE-2022-48839, affect devices running software version 3.3.1.0 and earlier. The most critical of these, CVE-2025-37165, allows exposure of VLAN configuration details through unintended network interfaces in router mode. This flaw has a CVSS v3.1 score of 7.5, requiring no authentication for exploitation.
CVE ID Description Severity CVSS Score Vector Attack Vector
CVE-2025-37165 VLAN information exposure in router mode High 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Network
CVE-2025-37166 DoS via crafted packets causing device shutdown High 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Network
CVE-2023-52340 Kernel packet processing memory corruption High 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Network
Hewlett Packard Enterprise (HPE) has identified four high-severity vulnerabilities in Aruba Networking Instant On devices.
CVE-2022-48839 IPv4/IPv6 packet handling vulnerability High 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Local
CVE-2025-37166 can lead to denial-of-service attacks by sending specially crafted packets to force access points into a non-responsive state, potentially necessitating physical resets.
Two additional kernel-level vulnerabilities, CVE-2023-52340 and CVE-2022-48839, impact the operating system's handling of IPv4 and IPv6 packets, potentially causing memory corruption and system crashes.
Affected Infrastructure and Exploitation Risk
The vulnerabilities affect HPE Networking Instant On Access Points and Aruba Instant On 1930 Switch Series running firmware 3.3.1.0 or earlier. HPE has confirmed that no other Aruba Networking products are impacted.
The vulnerabilities were identified by security researchers Daniel J Blueman and Petr Chelmar, as well as HPE's Instant On engineering team. As of the advisory publication date on Jan 13, 2026, there is no evidence of active exploitation.
HPE has released software version 3.3.2.0 to address these vulnerabilities. Automatic updates began in the week of Dec 10, 2025. Organizations should verify firmware versions and manually update devices if necessary, as no workarounds exist. Immediate patching is the recommended mitigation strategy.
HPE advises regular reviews of system management and security procedures to maintain infrastructure integrity and protect against future vulnerabilities.
Based on reporting by Cyber Security News.
