CVE-2026-38707

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:inhandnetworks:ir315_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir315:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:inhandnetworks:ir302_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir302:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:inhandnetworks:ir615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir615:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:inhandnetworks:ir305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir305:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-28 17:16

Updated : 2026-06-17 10:41


NVD link : CVE-2026-38707

Mitre link : CVE-2026-38707

CVE.ORG link : CVE-2026-38707


JSON object : View

Products Affected

inhandnetworks

  • ir315
  • ir315_firmware
  • ir302
  • ir615
  • ir305_firmware
  • ir305
  • ir302_firmware
  • ir615_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')