Executive brief
InHand Networks IR912 and IR915 industrial routers contain a critical security flaw in their file upload feature. This vulnerability allows an unauthorized person to remotely take full control of the device over the network. An attacker could disrupt industrial operations, access sensitive data, or use the compromised router as a foothold to attack other parts of the corporate network.
Technical details
A command injection vulnerability (CWE-77) exists in the file upload functionality of InHand Networks IR912 and IR915 routers running firmware version V1.0.0.r20042 and earlier. The flaw is triggered by improper neutralization of special elements within crafted input during the file upload process. A remote, unauthenticated attacker can exploit this over the network to execute arbitrary shell commands with root privileges. This allows for complete compromise of the device's integrity, confidentiality, and availability. Users are advised to check the vendor's security advisory for firmware updates.
Affected products
- InHand Networks IR912 V1.0.0.r20042 and earlier
- InHand Networks IR915 V1.0.0.r20042 and earlier
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory