9.8

CVE-2026-38702

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Inhandnetworks ≫ Ir315 Firmware Version < 1.0.121
   Inhandnetworks ≫ Ir315 Version -
Inhandnetworks ≫ Ir302 Firmware Version < 3.5.112
   Inhandnetworks ≫ Ir302 Version -
Inhandnetworks ≫ Ir615 Firmware Version < 1.0.121
   Inhandnetworks ≫ Ir615 Version -
Inhandnetworks ≫ Ir305 Firmware Version < 1.0.121
   Inhandnetworks ≫ Ir305 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.24% 0.653
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf
Vendor Advisory