← Vulnerability feed

Vulnerability record · CVE-2021-38480 · published 19 October 2021

CVE-2021-38480: Inhandnetworks ir615 firmware cross-site request forgery vulnerability

Inhandnetworks · Ir615 Firmware

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.

8.8 CVSS 3.1 High EPSS 0.56% · top 55.6% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score, v2 9.3
0.56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://us-cert.cisa.gov/ics/advisories/icsa-21-280-05 Third Party AdvisoryUS Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-280-05 Third Party AdvisoryUS Government Resource

Track CVE-2021-38480 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-38702Inhandnetworks ir315 firmware command injection vulnerabilityA command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw…EPSS 1.8%9.8CVE-2026-38703Inhandnetworks ir315 firmware command injection vulnerabilityA command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw…EPSS 1.8%9.8CVE-2026-38704Inhandnetworks ir315 firmware command injection vulnerabilityA command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firm…EPSS 1.8%9.8CVE-2026-38707Inhandnetworks ir315 firmware command injection vulnerabilityA command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware…EPSS 1.8%9.8CVE-2021-38474Inhandnetworks ir615 firmware improper restriction of authentication attempts vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. …EPSS 0.70%9.8CVE-2021-38462Inhandnetworks ir615 firmware weak password requirements vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with ob…EPSS 1.2%9.1CVE-2021-38470Inhandnetworks ir615 firmware os command injection vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands into the devic…EPSS 1.2%9.1CVE-2021-38478Inhandnetworks ir615 firmware os command injection vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-38480), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.