A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HInhandnetworks Inrouter302
HWInhandnetworksall versionsInhandnetworks Inrouter302 Firmware
OSInhandnetworks≤ 3.5.37
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-22600CRITICAL10.0PL ✓same product
Nieautoryzowany dostęp do MQTT w routerach InHand Networks InRouter 302/615
CVE-2023-22601CRITICAL10.0PL ✓same product
InHand Networks InRouter 302/615 — słaba losowość MQTT ClientID
CVE-2022-25932CRITICAL9.8PL ✓same product
Niekompletne poprawki privilege escalation w InHand Networks InRouter302
CVE-2023-22598HIGH7.2same product
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...
CVE-2023-22599HIGH7.0same product
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...