InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
References
| Link | Resource |
|---|---|
| https://www.inhand.com/wp-content/uploads/2026/06/InHand-PSA-2026-06_EN.pdf | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-18 17:16
Updated : 2026-06-22 17:47
NVD link : CVE-2026-38714
Mitre link : CVE-2026-38714
CVE.ORG link : CVE-2026-38714
JSON object : View
Products Affected
inhandnetworks
- ir912l-fq58
- ir915l-fq39-s_firmware
- ir912l-fq58_firmware
- ir915l-fq39-s
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
