Executive brief
InHand Networks industrial routers contain a critical security flaw in their Python application export feature. This vulnerability allows an unauthorized person to remotely take full control of the device over the network. An attacker could disrupt industrial operations, access sensitive data, or use the compromised router as a foothold to attack other parts of the corporate network.
Technical details
A command injection vulnerability (CWE-77) exists in the Python application export function of InHand Networks IR912 and IR915 routers. The flaw is rooted in improper neutralization of special elements within user-supplied input, which is subsequently processed by the system shell. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the device. Successful exploitation results in arbitrary code execution with root-level privileges, leading to full system compromise. The vulnerability affects version V1.0.0.r20042 and all prior versions.
Affected products
- InHand Networks IR912 V1.0.0.r20042 and earlier
- InHand Networks IR915 V1.0.0.r20042 and earlier
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory: InHand Networks PSA-2026-06 published