← All CVEs

CVE-2026-38717

critical · 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

9.8
CVSS
2.3%
EPSS (exploit prob.)
83rd
EPSS percentile
2026-06-18
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
inhandnetworksir915l-fq39-s_firmware< 1.0.0.r20044
inhandnetworksir915l-fq39-sall versions
inhandnetworksir912l-fq58_firmware< 1.0.0.r20044
inhandnetworksir912l-fq58all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-38717