Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection in InHand Networks IR302-IR615 VPN Firmware Allows Remote Root Access | |
| Weaknesses | CWE-269 CWE-78 |
Thu, 28 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-28T17:39:05.911Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38704
Updated: 2026-05-28T17:39:01.617Z
Status : Received
Published: 2026-05-28T17:16:21.413
Modified: 2026-05-28T18:16:31.880
Link: CVE-2026-38704
No data.
OpenCVE Enrichment
Updated: 2026-05-28T18:30:23Z