← Vulnerability feed

Vulnerability record · CVE-2026-38702 · published 28 May 2026

CVE-2026-38702: Inhandnetworks ir315 firmware command injection vulnerability

Inhandnetworks · Ir315 Firmware

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

9.8 CVSS 3.1 Critical EPSS 1.8% · top 22.8% CWE-77 · Command injection
9.8CVSS 3.1 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-38702 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-38703Inhandnetworks ir315 firmware command injection vulnerabilityA command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmw…EPSS 1.8%9.8CVE-2026-38704Inhandnetworks ir315 firmware command injection vulnerabilityA command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firm…EPSS 1.8%9.8CVE-2026-38707Inhandnetworks ir315 firmware command injection vulnerabilityA command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware…EPSS 1.8%9.8CVE-2021-38474Inhandnetworks ir615 firmware improper restriction of authentication attempts vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. …EPSS 0.70%9.8CVE-2021-38462Inhandnetworks ir615 firmware weak password requirements vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with ob…EPSS 1.2%9.1CVE-2021-38470Inhandnetworks ir615 firmware os command injection vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands into the devic…EPSS 1.2%9.1CVE-2021-38478Inhandnetworks ir615 firmware os command injection vulnerabilityInHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the…EPSS 1.2%8.8CVE-2022-28689Inhandnetworks ir302 firmware vulnerabilityA leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted network r…EPSS 0.95%

Source: NIST National Vulnerability Database (record CVE-2026-38702), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.