Executive brief
InHand Networks IR912 and IR915 industrial routers contain a critical security flaw in their Python configuration component. This vulnerability allows an unauthorized person to remotely take full control of the device over the network. An attacker could disrupt industrial operations, intercept data, or use the compromised router as a foothold to attack other systems on the internal network.
Technical details
A command injection vulnerability exists in the Python configuration function of InHand Networks IR912 and IR915 industrial routers (V1.0.0.r20042 and earlier). The flaw is categorized as CWE-77, where improper neutralization of special elements in user-provided input allows for the execution of arbitrary system commands. Because the vulnerable component runs with elevated privileges, a remote, unauthenticated attacker can execute commands as the root user. The attack vector is network-based with low complexity and requires no user interaction. Users are advised to refer to the InHand Networks security advisory for patching information.
Affected products
- InHand Networks IR912 firmware V1.0.0.r20042 and earlier
- InHand Networks IR915 firmware V1.0.0.r20042 and earlier
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory