InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-280-05 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2021-10-19T12:11:08.830902Z
Updated: 2024-09-17T03:13:52.768Z
Reserved: 2021-08-10T00:00:00
Link: CVE-2021-38480
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-10-19T13:15:11.347
Modified: 2024-11-21T06:17:12.397
Link: CVE-2021-38480
Redhat
No data.