Vulnerabilities (CVE)

Filtered by vendor Inhandnetworks Subscribe
Filtered by product Ir302
Total 25 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-26007 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 9.0 HIGH 7.2 HIGH
An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2022-26002 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 6.5 MEDIUM 7.2 HIGH
A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.
CVE-2022-25995 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.
CVE-2022-25172 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript and thus allowing an attacker, able to perform an XSS attack, to steal the session cookie.
CVE-2022-24910 1 Inhandnetworks 2 Ir302, Ir302 Firmware 2026-06-17 4.6 MEDIUM 6.7 MEDIUM
A buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.