Inhandnetworks manufactures a focused line of industrial and enterprise networking appliances, including the IR302, IR615, and InRouter 900 series, that serve as critical gateways and remote-access points in operational technology and distributed network environments. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting the memory-safety and command-handling demands of embedded firmware and management interfaces. The exposure recurs through OS command injection, command injection, cross-site scripting, and active debug code—weakness classes that are endemic to remotely manageable network devices and can enable direct system compromise or unauthorized administrative access. Defenders should treat this vendor's advisories as high-priority, particularly for internet-facing or remote-management instances, and inventory affected appliances across OT and enterprise network segments; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inhandnetworks over time
Signals from CVEs in this vendor scope (64 CVEs).
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-38704CRITICAL A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V | May 28, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-38702CRITICAL A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1 | May 28, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-38703CRITICAL A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1 | May 28, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-38707CRITICAL A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0. | May 28, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-38715CRITICAL InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. T | Jun 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2022-26085HIGH An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary com | May 12, 2022 | 8.8 | 34 | NO | NO |
CVE-2026-38714CRITICAL InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration fu | Jun 18, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-38716CRITICAL InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application expo | Jun 18, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-38717CRITICAL InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. T | Jun 18, 2026 | 9.8 | 33 | NO | NO |
CVE-2022-27276CRITICAL InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulner | Apr 10, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (64 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inhandnetworks.
Media articles that mention a CVE ID that affects a product developed by Inhandnetworks — matched by CVE ID, not by vendor name.