Vulnerability Description
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client requests from the help page. This may allow an attacker to perform a reflected cross-site scripting attack, which could allow an attacker to run code on behalf of the client browser.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inhandnetworks | Ir615 Firmware | 2.3.0.r4724 |
| Inhandnetworks | Ir615 | - |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-280-05Third Party AdvisoryUS Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-21-280-05Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-38466?
CVE-2021-38466 is a vulnerability with a CVSS score of 8.8 (HIGH). InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client requests from the help page. This may allow an attacker to perform a reflected ...
How severe is CVE-2021-38466?
CVE-2021-38466 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38466?
Check the references section above for vendor advisories and patch information. Affected products include: Inhandnetworks Ir615 Firmware, Inhandnetworks Ir615.