Junglewise Threat Intelligence

CVE-2026-38702: InHand Networks Industrial Routers command injection in Admin Access

CVE-2026-38702 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: InHand Networks IR305 firmware, InHand Networks IR302 firmware, InHand Networks IR615 firmware, InHand Networks IR315 firmware. Vendors: InHand Networks.

Executive brief

A security vulnerability has been identified in several InHand Networks industrial routers, which are used to provide connectivity for remote industrial equipment. An attacker can exploit this flaw to take complete control of the device with the highest level of administrative access. This could allow an unauthorized party to disrupt network operations, intercept data, or use the router as a foothold to attack other systems on the internal network.

Technical details

A command injection vulnerability exists within the 'Admin Access' feature of multiple InHand Networks router models (IR302, IR305, IR315, and IR615). The flaw is located in the firmware's handling of administrative inputs, where insufficient sanitization allows for the execution of arbitrary system commands. A remote attacker can exploit this vulnerability to bypass security controls and gain full ROOT-level access to the underlying operating system. This enables complete device compromise, including the ability to modify configurations, capture traffic, or pivot to connected local networks. The vulnerability affects IR302 firmware V3.5.108 and earlier, and IR305/IR315/IR615 firmware V1.0.118 and earlier.

Affected products

  • InHand Networks IR302 firmware V3.5.108 and earlier
  • InHand Networks IR305 firmware V1.0.118 and earlier
  • InHand Networks IR315 firmware V1.0.118 and earlier
  • InHand Networks IR615 firmware V1.0.118 and earlier

Timeline

  • 2026-05-28: disclosed: Initial publication of CVE-2026-38702

References

Related threats