CVE-2026-38704

A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:inhandnetworks:ir315_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir315:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:inhandnetworks:ir302_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir302:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:inhandnetworks:ir615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir615:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:inhandnetworks:ir305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir305:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-28 17:16

Updated : 2026-06-17 10:41


NVD link : CVE-2026-38704

Mitre link : CVE-2026-38704

CVE.ORG link : CVE-2026-38704


JSON object : View

Products Affected

inhandnetworks

  • ir315
  • ir315_firmware
  • ir302
  • ir615
  • ir305_firmware
  • ir305
  • ir302_firmware
  • ir615_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')