The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HInhandnetworks Inrouter302
HWInhandnetworksall versionsInhandnetworks Inrouter302 Firmware
OSInhandnetworks< 3.5.56
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
Related vulnerabilities
CVE-2023-22600CRITICAL10.0PL ✓same product
Nieautoryzowany dostęp do MQTT w routerach InHand Networks InRouter 302/615
CVE-2023-22601CRITICAL10.0PL ✓same product
InHand Networks InRouter 302/615 — słaba losowość MQTT ClientID
CVE-2023-22598HIGH7.2same product
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...
CVE-2023-22599HIGH7.0same product
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-...
CVE-2022-21182HIGH8.8same product
A privilege escalation vulnerability exists in the router configuration import functionality of InHand Network...