Vulnerability Description
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inhandnetworks | Inrouter 900 Firmware | < 1.0.0.r11700 |
| Inhandnetworks | Inrouter 900 | - |
Related Weaknesses (CWE)
References
- https://drive.google.com/drive/folders/1zJ2dGrKar-WTlYz13v1f0BIsoIm3aU0l?usp=shaExploitThird Party Advisory
- https://github.com/wu610777031/IoT_Hunter/blob/main/Inhand%20InRouter%20900%20In
- https://drive.google.com/drive/folders/1zJ2dGrKar-WTlYz13v1f0BIsoIm3aU0l?usp=shaExploitThird Party Advisory
- https://github.com/wu610777031/IoT_Hunter/blob/main/Inhand%20InRouter%20900%20In
FAQ
What is CVE-2022-27272?
CVE-2022-27272 is a vulnerability with a CVSS score of 9.8 (CRITICAL). InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered...
How severe is CVE-2022-27272?
CVE-2022-27272 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-27272?
Check the references section above for vendor advisories and patch information. Affected products include: Inhandnetworks Inrouter 900 Firmware, Inhandnetworks Inrouter 900.