Critical severity9.8NVD Advisory· Published Jun 18, 2026· Updated Jun 22, 2026
CVE-2026-38717
CVE-2026-38717
Description
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
Affected products
4- cpe:2.3:o:inhandnetworks:ir912l-fq58_firmware:*:*:*:*:*:*:*:*Range: <1.0.0.r20044
- cpe:2.3:o:inhandnetworks:ir915l-fq39-s_firmware:*:*:*:*:*:*:*:*Range: <1.0.0.r20044
- Range: <=V1.0.0.r20042
- Range: <=V1.0.0.r20042
Patches
Vulnerability mechanics
References
1- www.inhand.com/wp-content/uploads/2026/06/InHand-PSA-2026-06_EN.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.