Junglewise Threat Intelligence

CVE-2026-38716: InHand Networks IR912 and IR915 command injection in Python export function

CVE-2026-38716 · Severity: critical · CVSS 9.8 · Published 2026-06-18

Technologies: InHand Networks IR912, InHand Networks IR915. Vendors: InHand Networks.

Executive brief

InHand Networks industrial routers contain a critical security flaw in their Python application export feature. This vulnerability allows an unauthorized person to remotely take full control of the device over the network. An attacker could disrupt industrial operations, access sensitive data, or use the compromised router as a foothold to attack other parts of the corporate network.

Technical details

A command injection vulnerability (CWE-77) exists in the Python application export function of InHand Networks IR912 and IR915 routers. The flaw is rooted in improper neutralization of special elements within user-supplied input, which is subsequently processed by the system shell. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to the device. Successful exploitation results in arbitrary code execution with root-level privileges, leading to full system compromise. The vulnerability affects version V1.0.0.r20042 and all prior versions.

Affected products

  • InHand Networks IR912 V1.0.0.r20042 and earlier
  • InHand Networks IR915 V1.0.0.r20042 and earlier

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory: InHand Networks PSA-2026-06 published

References

Related threats