CVE-2026-38715 Details
Description
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
A command injection vulnerability has been identified in InHand Networks IR912 and IR915 Industrial Routers, both running firmware version V1.0.0.r20042 and earlier. This vulnerability allows remote attackers to execute arbitrary commands with root privileges by exploiting the log viewing function.
Users are advised to update to InHand Networks IR912 and IR915 firmware version IR9-V1.0.0.r20044.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.inhand.com/wp-content/uploads/2026/06/InHand-PSA-2026-06_EN.pdf | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| inhandnetworks ir915l-fq39-s firmware | < 1.0.0.r20044 |
CPE
Remediation
| |
| inhandnetworks ir915l-fq39-s | All versions |
CPE
Remediation
| |
| inhandnetworks ir912l-fq58 firmware | < 1.0.0.r20044 |
CPE
Remediation
| |
| inhandnetworks ir912l-fq58 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | Initial Analysis | [email protected] |
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 18, 2026 | New CVE Received | [email protected] |