Junglewise Threat Intelligence

CVE-2026-38703: InHand Networks IR Series command injection in ZeroTier VPN

CVE-2026-38703 · Severity: info · Published 2026-05-28

Technologies: InHand Networks IR305 firmware, InHand Networks IR302 firmware, InHand Networks IR615 firmware, InHand Networks IR315 firmware. Vendors: InHand Networks.

Executive brief

A security vulnerability has been identified in several InHand Networks industrial routers, specifically within the ZeroTier VPN functionality. This flaw allows a remote attacker to take complete control of the device with the highest level of administrative access (ROOT). Such an exploit could lead to unauthorized access to the internal network, data interception, or a total disruption of the router's operations.

Technical details

A command injection vulnerability exists in the ZeroTier VPN implementation within the firmware of multiple InHand Networks industrial router models. The flaw is located in the handling of ZeroTier configuration or management traffic, where insufficient input validation allows for the execution of arbitrary system commands. An attacker can exploit this over the network to gain unauthorized ROOT-level access to the underlying operating system. Affected models include IR302 (V3.5.108 and earlier), IR305 (V1.0.118 and earlier), IR315 (V1.0.118 and earlier), and IR615 (V1.0.118 and earlier). Users are advised to check for firmware updates from the vendor to mitigate this risk.

Affected products

  • InHand Networks IR302 firmware V3.5.108 and earlier
  • InHand Networks IR305 firmware V1.0.118 and earlier
  • InHand Networks IR315 firmware V1.0.118 and earlier
  • InHand Networks IR615 firmware V1.0.118 and earlier

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats