Inhandnetworks
Inhandnetworks Ir615 Firmware: vulnerabilidades y CVE
Inhandnetworks Ir615 Firmware tiene 17 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses4
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-38707 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers… |
| CVE-2026-38704 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions.… |
| CVE-2026-38703 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers… |
| CVE-2026-38702 | Crítica (9.8) | 1.8% | — | 28 may 2026 | A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers… |
| CVE-2021-38486 | Alta (8.5) | 0.80% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the affected product without any requirements to create an account, which may allow an attacker to have… |
| CVE-2021-38484 | Alta (7.2) | 2.8% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicious files to the server, which may allow an attacker, acting as an… |
| CVE-2021-38482 | Media (4.8) | 0.57% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 website used to control the router is vulnerable to stored cross-site scripting, which may allow an attacker to hijack sessions of users connected to… |
| CVE-2021-38480 | Alta (8.8) | 0.56% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an… |
| CVE-2021-38478 | Crítica (9.1) | 1.2% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute tool to inject commands into the device. This may allow the attacker to remotely run commands on… |
| CVE-2021-38476 | Media (5.3) | 0.78% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and validates the existence of a username. This may allow an attacker to enumerate different user accounts. |
| CVE-2021-38474 | Crítica (9.8) | 0.70% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for the login page of the product. This may allow an attacker to execute a brute-force password attack… |
| CVE-2021-38472 | Media (4.7) | 0.69% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTIONS header, which an attacker may take advantage of by sending a link to an administrator that frames… |
| CVE-2021-38470 | Crítica (9.1) | 1.2% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to inject commands into the device. This may allow the attacker to remotely run commands on behalf of… |
| CVE-2021-38468 | Media (4.8) | 0.57% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to stored cross-scripting, which may allow an attacker to hijack sessions of users connected to the system. |
| CVE-2021-38466 | Media (6.1) | 0.69% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client requests from the help page. This may allow an attacker to perform a reflected cross-site… |
| CVE-2021-38464 | Alta (7.4) | 0.33% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption strength, which may allow an attacker to intercept the communication and steal sensitive information or hijack the session. |
| CVE-2021-38462 | Crítica (9.8) | 1.2% | — | 19 oct 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This may allow an attacker with obtained user credentials to enumerate passwords and impersonate other… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.