Executive brief
InHand Networks industrial routers contain a critical security flaw in their log viewing feature. This vulnerability allows an unauthorized person to remotely take full control of the device over the network. An attacker could disrupt industrial operations, access sensitive data, or use the device as a foothold to attack other parts of the corporate network.
Technical details
A command injection vulnerability (CWE-77) exists in the log viewing function of InHand Networks IR912 and IR915 routers. The flaw is caused by improper neutralization of special elements in user-supplied input, which is subsequently passed to a system shell. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the device's web interface. Successful exploitation results in arbitrary code execution with root privileges, leading to a complete compromise of the device's confidentiality, integrity, and availability.
Affected products
- InHand Networks IR912 V1.0.0.r20042 and earlier
- InHand Networks IR915 V1.0.0.r20042 and earlier
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory