Junglewise Threat Intelligence

CVE-2026-38707: InHand Networks Industrial Routers command injection in IPSec VPN

CVE-2026-38707 · Severity: info · Published 2026-05-28

Technologies: InHand Networks IR305 firmware, InHand Networks IR302 firmware, InHand Networks IR615 firmware, InHand Networks IR315 firmware. Vendors: InHand Networks.

Executive brief

A security vulnerability has been identified in several InHand Networks industrial routers, which are used to provide secure remote connectivity for industrial equipment. An attacker can exploit a flaw in the VPN feature to take complete control of the device with the highest level of administrative access (ROOT). This could allow an unauthorized user to disrupt network traffic, access sensitive data, or use the router as a foothold to attack other systems on the internal network.

Technical details

A command injection vulnerability exists within the IPSec VPN implementation of InHand Networks IR302, IR305, IR315, and IR615 routers. The flaw is located in the firmware's handling of VPN configurations, where insufficient input validation allows for the execution of arbitrary system commands. A remote attacker can exploit this vulnerability to bypass security controls and gain ROOT-level access to the underlying operating system. The vulnerability affects IR302 firmware V3.5.108, and IR305, IR315, and IR615 firmware V1.0.118 and earlier versions. Users are advised to check for firmware updates from the vendor to mitigate this risk.

Affected products

  • InHand Networks IR302 firmware V3.5.108 and earlier
  • InHand Networks IR305 firmware V1.0.118 and earlier
  • InHand Networks IR315 firmware V1.0.118 and earlier
  • InHand Networks IR615 firmware V1.0.118 and earlier

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats