CRITICAL · 9.8

CVE-2026-38702

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier ...

Vulnerability Description

A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
InhandnetworksIr315 Firmware< 1.0.121
InhandnetworksIr315-
InhandnetworksIr302 Firmware< 3.5.112
InhandnetworksIr302-
InhandnetworksIr615 Firmware< 1.0.121
InhandnetworksIr615-
InhandnetworksIr305 Firmware< 1.0.121
InhandnetworksIr305-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-38702?

CVE-2026-38702 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier ...

How severe is CVE-2026-38702?

CVE-2026-38702 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2026-38702?

Check the references section above for vendor advisories and patch information. Affected products include: Inhandnetworks Ir315 Firmware, Inhandnetworks Ir315, Inhandnetworks Ir302 Firmware, Inhandnetworks Ir302, Inhandnetworks Ir615 Firmware.