Junglewise Threat Intelligence

CVE-2026-38718: InHand Networks IR912 and IR915 buffer overflow in device registration

CVE-2026-38718 · Severity: high · CVSS 7.5 · Published 2026-06-18

Technologies: InHand Networks IR912, InHand Networks IR915. Vendors: InHand Networks.

Executive brief

InHand Networks industrial routers are used to provide connectivity for remote industrial equipment. A security flaw in the device registration process allows a remote attacker to crash the device, leading to a loss of connectivity and potential disruption of industrial operations. This could prevent administrators from managing the equipment or receiving critical data from the field.

Technical details

A classic buffer overflow (CWE-120) exists in the device registration function of InHand Networks IR912 and IR915 routers. The vulnerability is caused by a buffer copy without checking the size of the input during the registration process. A remote, unauthenticated attacker can exploit this over the network by sending a specially crafted request. Successful exploitation results in a denial of service (DoS) condition, crashing the target device. The issue affects firmware versions up to and including V1.0.0.r20042.

Affected products

  • InHand Networks IR912 V1.0.0.r20042 and earlier
  • InHand Networks IR915 V1.0.0.r20042 and earlier

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References

Related threats