Executive brief
InHand Networks industrial routers are used to provide connectivity for remote industrial equipment. A security flaw in the device registration process allows a remote attacker to crash the device, leading to a loss of connectivity and potential disruption of industrial operations. This could prevent administrators from managing the equipment or receiving critical data from the field.
Technical details
A classic buffer overflow (CWE-120) exists in the device registration function of InHand Networks IR912 and IR915 routers. The vulnerability is caused by a buffer copy without checking the size of the input during the registration process. A remote, unauthenticated attacker can exploit this over the network by sending a specially crafted request. Successful exploitation results in a denial of service (DoS) condition, crashing the target device. The issue affects firmware versions up to and including V1.0.0.r20042.
Affected products
- InHand Networks IR912 V1.0.0.r20042 and earlier
- InHand Networks IR915 V1.0.0.r20042 and earlier
Timeline
- 2026-06-18: disclosed
- 2026-06-18: advisory