Inhandnetworks
Inhandnetworks Ir302 Firmware: vulnerabilidades y CVE
Inhandnetworks Ir302 Firmware tiene 25 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses4
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-38707 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers… |
| CVE-2026-38704 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions.… |
| CVE-2026-38703 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers… |
| CVE-2026-38702 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers… |
| CVE-2022-30543 | Alta (8.8) | 0.91% | — | 9 nov 2022 | A leftover debug code vulnerability exists in the console infct functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to execution of privileged operations. An… |
| CVE-2022-29888 | Alta (8.1) | 1.5% | — | 9 nov 2022 | A leftover debug code vulnerability exists in the httpd port 4444 upload.cgi functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can… |
| CVE-2022-29481 | Media (6.5) | 0.79% | — | 9 nov 2022 | A leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker… |
| CVE-2022-28689 | Alta (8.8) | 0.95% | — | 9 nov 2022 | A leftover debug code vulnerability exists in the console support functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a… |
| CVE-2022-26023 | Media (6.5) | 0.80% | — | 9 nov 2022 | A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A specially-crafted series of network requests can lead to disabling security features. An attacker… |
| CVE-2022-27172 | Alta (8.8) | 1.1% | — | 12 may 2022 | A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can… |
| CVE-2022-26782 | Alta (8.8) | 3.3% | — | 12 may 2022 | Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can… |
| CVE-2022-26781 | Alta (8.8) | 2.9% | — | 12 may 2022 | Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can… |
| CVE-2022-26780 | Alta (8.8) | 3.3% | — | 12 may 2022 | Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can… |
| CVE-2022-26518 | Alta (8.8) | 4.9% | — | 12 may 2022 | An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An… |
| CVE-2022-26510 | Media (6.5) | 1.3% | — | 12 may 2022 | A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of… |
| CVE-2022-26420 | Alta (8.8) | 5.9% | — | 12 may 2022 | An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An… |
| CVE-2022-26085 | Alta (8.8) | 13% | — | 12 may 2022 | An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an… |
| CVE-2022-26075 | Alta (8.8) | 5.9% | — | 12 may 2022 | An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An… |
| CVE-2022-26042 | Alta (8.8) | 8.6% | — | 12 may 2022 | An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send… |
| CVE-2022-26020 | Media (6.5) | 0.68% | — | 12 may 2022 | An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to increased privileges. An attacker… |
| CVE-2022-26007 | Alta (7.2) | 5.4% | — | 12 may 2022 | An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence… |
| CVE-2022-26002 | Alta (7.2) | 3.4% | — | 12 may 2022 | A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send… |
| CVE-2022-25995 | Alta (8.8) | 2.9% | — | 12 may 2022 | A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a… |
| CVE-2022-25172 | Media (6.1) | 1.0% | — | 12 may 2022 | An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4. The session cookie misses the HttpOnly flag, making it accessible via JavaScript… |
| CVE-2022-24910 | Media (6.7) | 1.3% | — | 12 may 2022 | A buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.