CVE-2026-38707
critical · 9.8A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
9.8
CVSS
1.2%
EPSS (exploit prob.)
68th
EPSS percentile
2026-05-28
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-77
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| inhandnetworks | ir315_firmware | < 1.0.121 |
| inhandnetworks | ir315 | all versions |
| inhandnetworks | ir302_firmware | < 3.5.112 |
| inhandnetworks | ir302 | all versions |
| inhandnetworks | ir615_firmware | < 1.0.121 |
| inhandnetworks | ir615 | all versions |
| inhandnetworks | ir305_firmware | < 1.0.121 |
| inhandnetworks | ir305 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-38707