Junglewise Threat Intelligence

CVE-2026-38704: InHand Networks IR Series command injection in WireGuard VPN

CVE-2026-38704 · Severity: info · Published 2026-05-28

Technologies: InHand Networks IR305 firmware, InHand Networks IR302 firmware, InHand Networks IR615 firmware, InHand Networks IR315 firmware. Vendors: InHand Networks.

Executive brief

A security vulnerability has been identified in several InHand Networks industrial routers, specifically within their WireGuard VPN functionality. These devices are commonly used to provide secure remote connectivity for industrial equipment and infrastructure. An attacker could exploit this flaw to take complete control of the router with administrative (root) privileges, potentially allowing them to intercept network traffic, disrupt operations, or move laterally into the internal corporate network.

Technical details

A command injection vulnerability exists in the WireGuard VPN implementation of multiple InHand Networks industrial router models (IR302, IR305, IR315, IR615). The flaw is located within the firmware's handling of WireGuard configuration or management parameters, where insufficient input validation allows for the execution of arbitrary system commands. A remote attacker can exploit this vulnerability to bypass security controls and gain full ROOT-level access to the underlying operating system. The vulnerability affects IR302 firmware V3.5.108 and earlier, and IR305/IR315/IR615 firmware V1.0.118 and earlier. Users are advised to consult the vendor's security advisory for patch information.

Affected products

  • InHand Networks IR302 firmware V3.5.108 and earlier
  • InHand Networks IR305 firmware V1.0.118 and earlier
  • InHand Networks IR315 firmware V1.0.118 and earlier
  • InHand Networks IR615 firmware V1.0.118 and earlier

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats