A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
The vulnerability (CWE-77) results from improper neutralization of special characters in input data passed to system commands within the ZeroTier VPN function. An attacker can provide specially crafted input data that will be interpreted as operating system commands and executed with the highest privileges. The network attack vector (AV:N) without authentication requirement (PR:N) and user interaction (UI:N) makes it possible to conduct the attack remotely and fully automatically.
An attacker gains full ROOT privileges on a remote device, enabling complete takeover of the router, modification of its configuration, interception of network traffic, and potential use of the device as an entry point to the internal network.
Patches available from the manufacturer should be applied in accordance with the references (InHand PSA-2026-05). It is recommended to immediately update the firmware to a patched version and — until the patch is deployed — consider disabling the ZeroTier VPN function or restricting access to the device management interface only to trusted networks.
InHand Networks IR302 firmware V3.5.108 and earlier, IR305 firmware V1.0.118 and earlier, IR315 firmware V1.0.118 and earlier, IR615 firmware V1.0.118 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HInhandnetworks Ir302
HWInhandnetworksall versionsInhandnetworks Ir302 Firmware
OSInhandnetworks< 3.5.112Inhandnetworks Ir305
HWInhandnetworksall versionsInhandnetworks Ir305 Firmware
OSInhandnetworks< 1.0.121Inhandnetworks Ir315
HWInhandnetworksall versionsInhandnetworks Ir315 Firmware
OSInhandnetworks< 1.0.121Inhandnetworks Ir615
HWInhandnetworksall versionsInhandnetworks Ir615 Firmware
OSInhandnetworks< 1.0.121
Related vulnerabilities
Command injection w funkcji IPSec VPN urządzeń InHand Networks — dostęp ROOT
Command injection w funkcji WireGuard VPN urządzeń InHand Networks
Command injection w firmware InHand Networks IR302/IR315/IR615 — dostęp ROOT
CSRF w routerze InHand Networks IR615 — zdalne wykonanie akcji administracyjnych
Command Injection w routerze InHand Networks IR615 via narzędzie ping