CRITICAL🇵🇱 Wersja polska

CVE-2026-38703

CVSS 9.8v3.1pub. 2026-05-28upd. 2026-05-29

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

🤖 AI Analysis
How it works

The vulnerability (CWE-77) results from improper neutralization of special characters in input data passed to system commands within the ZeroTier VPN function. An attacker can provide specially crafted input data that will be interpreted as operating system commands and executed with the highest privileges. The network attack vector (AV:N) without authentication requirement (PR:N) and user interaction (UI:N) makes it possible to conduct the attack remotely and fully automatically.

Impact

An attacker gains full ROOT privileges on a remote device, enabling complete takeover of the router, modification of its configuration, interception of network traffic, and potential use of the device as an entry point to the internal network.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references (InHand PSA-2026-05). It is recommended to immediately update the firmware to a patched version and — until the patch is deployed — consider disabling the ZeroTier VPN function or restricting access to the device management interface only to trusted networks.

Who is affected

InHand Networks IR302 firmware V3.5.108 and earlier, IR305 firmware V1.0.118 and earlier, IR315 firmware V1.0.118 and earlier, IR615 firmware V1.0.118 and earlier.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Inhandnetworks Ir302

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Ir302 Firmware

    OS
    Inhandnetworks
    < 3.5.112
  • Inhandnetworks Ir305

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Ir305 Firmware

    OS
    Inhandnetworks
    < 1.0.121
  • Inhandnetworks Ir315

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Ir315 Firmware

    OS
    Inhandnetworks
    < 1.0.121
  • Inhandnetworks Ir615

    HW
    Inhandnetworks
    all versions
  • Inhandnetworks Ir615 Firmware

    OS
    Inhandnetworks
    < 1.0.121
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2026-38707CRITICAL9.8PL ✓same product

Command injection w funkcji IPSec VPN urządzeń InHand Networks — dostęp ROOT

CVE-2026-38704CRITICAL9.8PL ✓same product

Command injection w funkcji WireGuard VPN urządzeń InHand Networks

CVE-2026-38702CRITICAL9.8PL ✓same product

Command injection w firmware InHand Networks IR302/IR315/IR615 — dostęp ROOT

CVE-2021-38480CRITICAL9.6PL ✓same product

CSRF w routerze InHand Networks IR615 — zdalne wykonanie akcji administracyjnych

CVE-2021-38470CRITICAL9.1PL ✓same product

Command Injection w routerze InHand Networks IR615 via narzędzie ping