Impact
A command injection flaw exists in the IPSec VPN component of InHand Networks firmware. The vulnerability allows an attacker to send crafted data that is directly executed as a system command, giving them root privileges on the device.
Affected Systems
InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and all earlier firmware releases of these models are affected.
Risk and Exploitability
The CVSS score is not provided, but the nature of the flaw – remote command injection leading to root privileges – implies a high to critical severity. The EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog. It is inferred that exploitation likely requires network access to the device’s VPN management interface and that no authentication or privilege checks are performed, making exploitation straightforward for anyone with that reach. Based on the description, the likelihood of successful exploitation is high if the device is reachable.
OpenCVE Enrichment