InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
References
| Link | Resource |
|---|---|
| https://www.inhand.com/wp-content/uploads/2026/06/InHand-PSA-2026-06_EN.pdf | Vendor Advisory |
Configurations
History
22 Jun 2026, 17:47
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Inhandnetworks ir912l-fq58 Firmware
Inhandnetworks Inhandnetworks ir912l-fq58 Inhandnetworks ir915l-fq39-s Inhandnetworks ir915l-fq39-s Firmware |
|
| CPE | cpe:2.3:h:inhandnetworks:ir912l-fq58:-:*:*:*:*:*:*:* cpe:2.3:h:inhandnetworks:ir915l-fq39-s:-:*:*:*:*:*:*:* cpe:2.3:o:inhandnetworks:ir912l-fq58_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:inhandnetworks:ir915l-fq39-s_firmware:*:*:*:*:*:*:*:* |
|
| References | () https://www.inhand.com/wp-content/uploads/2026/06/InHand-PSA-2026-06_EN.pdf - Vendor Advisory |
18 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-18 17:16
Updated : 2026-06-22 17:47
NVD link : CVE-2026-38714
Mitre link : CVE-2026-38714
CVE.ORG link : CVE-2026-38714
JSON object : View
Products Affected
inhandnetworks
- ir912l-fq58_firmware
- ir915l-fq39-s
- ir912l-fq58
- ir915l-fq39-s_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
