


Perceptive Security
SOC/SIEM Consultancy

A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.11…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 19:09:38
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Critical Infrastructure
A command injection vulnerability has been discovered in the ZeroTier VPN feature of multiple InHand Networks industrial router models including IR302, IR305, IR315, and IR615. The vulnerability affects specific firmware versions and allows attackers to gain ROOT privileges on remote target devices. This represents a critical security flaw in industrial networking equipment that could provide attackers with complete system control. The vulnerability impacts the ZeroTier VPN functionality specifically, which is commonly used for secure remote access in industrial environments. Given the ROOT privilege escalation capability and remote exploitation potential, this poses significant risks to operational technology networks.
Technical details
Mitigation steps:
Affected products:
InHand Networks IR302
InHand Networks IR305
InHand Networks IR315
InHand Networks IR615
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-38703
https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
