


Perceptive Security
SOC/SIEM Consultancy

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, …
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 20:05:25
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
A command injection vulnerability exists in the IPSec VPN feature of multiple InHand Networks router models including IR302, IR305, IR315, and IR615. The vulnerability affects firmware versions V3.5.108 and V1.0.118 and earlier versions respectively. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. The vulnerability represents a critical security risk as it allows complete system compromise through remote command execution. The affected devices are industrial routers commonly used in network infrastructure deployments.
Technical details
Mitigation steps:
Affected products:
InHand Networks IR302
InHand Networks IR305
InHand Networks IR315
InHand Networks IR615
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-38707
https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
