A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
References
| Link | Resource |
|---|---|
| https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
No history.
Information
Published : 2026-05-28 17:16
Updated : 2026-06-17 10:41
NVD link : CVE-2026-38707
Mitre link : CVE-2026-38707
CVE.ORG link : CVE-2026-38707
JSON object : View
Products Affected
inhandnetworks
- ir315
- ir315_firmware
- ir302
- ir615
- ir305_firmware
- ir305
- ir302_firmware
- ir615_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
