iND Co., Ltd. Products OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability allowing arbitrary operating system commands to be executed has been identified in multiple products by iND Co., Ltd. This vulnerability could also lead to the unauthorized access of sensitive information. Affected products include various models of mobile routers, with specific firmware versions listed in the product status section.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution and access to sensitive information.

Remediation

Users are advised to update the firmware to the latest version. For HL330-DLS, which is no longer supported, it is possible to update using the firmware for HL320-DLS, as they share the same firmware. Instructions for updating other affected products are also available on the iND Co., Ltd. website.

Added: Aug 29, 2025, 5:21 AM
Updated: Aug 29, 2025, 5:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
0.0
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.