LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-38707

inhandnetworks · ir315 firmware

Published
CVSS9.8
Severitycritical
WeaknessCWE-77
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-38707

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-38707.