PatchSiren

InHand Networks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL InHand Networks CVE published 2026-05-28

CVE-2026-38707

A critical command injection vulnerability in the IPSec VPN feature of multiple InHand Networks industrial router firmware versions allows unauthenticated remote attackers to execute arbitrary commands with ROOT privileges. The vulnerability affects IR302 (V3.5.108 and earlier), IR305, IR315, and IR615 (all V1.0.118 and earlier). The CVSS 3.1 score of 9.8 reflects network attack vector, low complexity, no [truncated]

CRITICAL InHand Networks CVE published 2026-05-28

CVE-2026-38704

A critical command injection vulnerability exists in the WireGuard VPN feature of multiple InHand Networks industrial router firmware versions. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands with ROOT privileges. Affected products include IR302 (V3.5.108 and earlier), IR305 (V1.0.118 and earlier), IR315 (V1.0.118 and earlier), and IR615 (V1.0.118 and earlier). The [truncated]

CRITICAL InHand Networks CVE published 2026-05-28

CVE-2026-38703

A critical command injection vulnerability in the ZeroTier VPN feature of InHand Networks industrial routers allows unauthenticated remote attackers to execute arbitrary commands with ROOT privileges. The vulnerability affects IR302 (V3.5.108 and earlier), IR305, IR315, and IR615 (all V1.0.118 and earlier). The CVSS 3.1 score of 9.8 reflects network attack vector, low complexity, no privileges required, a [truncated]

CRITICAL InHand Networks CVE published 2026-05-28

CVE-2026-38702

A critical command injection vulnerability in InHand Networks industrial router firmware allows unauthenticated remote attackers to obtain root privileges. The vulnerability resides in the Admin Access feature of multiple IR-series router models. Affected firmware versions include IR302 V3.5.108, IR305 V1.0.118, IR315 V1.0.118, IR615 V1.0.118, and earlier releases. The CVSS 3.1 score of 9.8 reflects netwo [truncated]