CVE-2026-38707

A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:inhandnetworks:ir315_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir315:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:inhandnetworks:ir302_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir302:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:inhandnetworks:ir615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir615:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:inhandnetworks:ir305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir305:-:*:*:*:*:*:*:*

History

29 May 2026, 14:08

Type Values Removed Values Added
References () https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf - () https://www.inhand.com/wp-content/uploads/InHand-PSA-2026-05_EN.pdf - Vendor Advisory
First Time Inhandnetworks ir305
Inhandnetworks
Inhandnetworks ir305 Firmware
Inhandnetworks ir315
Inhandnetworks ir615
Inhandnetworks ir302 Firmware
Inhandnetworks ir315 Firmware
Inhandnetworks ir615 Firmware
Inhandnetworks ir302
CPE cpe:2.3:h:inhandnetworks:ir305:-:*:*:*:*:*:*:*
cpe:2.3:o:inhandnetworks:ir615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:inhandnetworks:ir315_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir615:-:*:*:*:*:*:*:*
cpe:2.3:o:inhandnetworks:ir302_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:inhandnetworks:ir305_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir315:-:*:*:*:*:*:*:*
cpe:2.3:h:inhandnetworks:ir302:-:*:*:*:*:*:*:*

28 May 2026, 18:16

Type Values Removed Values Added
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

28 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 17:16

Updated : 2026-05-29 14:08


NVD link : CVE-2026-38707

Mitre link : CVE-2026-38707

CVE.ORG link : CVE-2026-38707


JSON object : View

Products Affected

inhandnetworks

  • ir615
  • ir315
  • ir305
  • ir302_firmware
  • ir302
  • ir305_firmware
  • ir315_firmware
  • ir615_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')