InHand Networks IR302
Moderate fix1 remedy
cpe:2.3:h:inhandnetworks:ir302:*:*:*:*:*:*:*, +1 more
Moderate fix1 remedy
- <= V3.5.108
A command injection vulnerability has been identified in the IPSec VPN feature of InHand Networks Industrial Routers IR302, IR305, IR315, and IR615, all running vulnerable firmware versions. This vulnerability allows attackers to execute arbitrary commands with root privileges on the affected devices.
Exploitation of this vulnerability grants root privileges on the affected device, allowing for complete control over the device's functions and capabilities.
Users are advised to update to the following fixed firmware versions: IR302: InRouter3XX-V3.5.112, IR305: InRouter3X5-V1.0.121, IR315: InRouter3X5-V1.0.121, IR615: InRouter6XS-V1.0.121.