PatchSiren cyber security CVE debrief
CVE-2026-38702 InHand Networks CVE debrief
A critical command injection vulnerability in InHand Networks industrial router firmware allows unauthenticated remote attackers to obtain root privileges. The vulnerability resides in the Admin Access feature of multiple IR-series router models. Affected firmware versions include IR302 V3.5.108, IR305 V1.0.118, IR315 V1.0.118, IR615 V1.0.118, and earlier releases. The CVSS 3.1 score of 9.8 reflects network attack vector, low complexity, no privileges required, and high impact across confidentiality, integrity, and availability. The vendor has published a security advisory acknowledging this vulnerability. Organizations using affected InHand Networks industrial routers should prioritize patching given the unauthenticated remote exploitation path and complete system compromise capability.
- Vendor
- InHand Networks
- Product
- IR-series industrial routers (IR302, IR305, IR315, IR615)
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-29
Who should care
Organizations operating InHand Networks IR-series industrial routers in manufacturing, utilities, transportation, and critical infrastructure sectors. Security teams responsible for OT/ICS network security and industrial gateway management. Managed service providers supporting industrial IoT deployments using affected router models.
Technical summary
The vulnerability is classified as CWE-77 (Command Injection) affecting the Admin Access feature of InHand Networks industrial routers. Multiple firmware versions across four product lines are impacted: IR302 (V3.5.108 and earlier), IR305 (V1.0.118 and earlier), IR315 (V1.0.118 and earlier), and IR615 (V1.0.118 and earlier). The attack requires no authentication and can be executed remotely over the network with low complexity, resulting in complete compromise of the target device with root privileges. The vulnerability is currently undergoing analysis in the NVD.
Defensive priority
critical
Recommended defensive actions
- Apply firmware updates from InHand Networks when available per vendor security advisory
- Restrict network access to administrative interfaces on affected IR302, IR305, IR315, and IR615 routers
- Monitor for unauthorized access attempts to Admin Access features
- Review device logs for indicators of compromise if patching is delayed
- Consider network segmentation for industrial router deployments until patches are applied
Evidence notes
Vulnerability description sourced from NVD CVE record. Vendor attribution based on reference domain candidate 'Inhand' with low confidence; vendor name marked as 'Unknown Vendor' in source data with review flag set. Affected product versions and firmware details from CVE description. CVSS vector and weakness classification (CWE-77: Command Injection) from NVD metadata. Vendor advisory link present in references.
Official resources
-
CVE-2026-38702 CVE record
CVE.org
-
CVE-2026-38702 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-28