Medium severity6.5NVD Advisory· Published Jan 12, 2023· Updated Jun 17, 2026
CVE-2023-22597
CVE-2023-22597
Description
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-319: Cleartext Transmission of Sensitive Information. They use an unsecured channel to communicate with the cloud platform by default. An unauthorized user could intercept this communication and steal sensitive information such as configuration information and MQTT credentials; this could allow MQTT command injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:inhandnetworks:inrouter302_firmware:*:*:*:*:*:*:*:*Range: <3.5.56
- cpe:2.3:o:inhandnetworks:inrouter615-s_firmware:*:*:*:*:*:*:*:*Range: <2.3.0.r5542
- Range: <InRouter6XX-S-V2.3.0.r5542
<IR302 V3.5.56+ 1 more
- (no CPE)range: <IR302 V3.5.56
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-23-012-03nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.