Vulnerabilities > Inhandnetworks > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-01-12 CVE-2023-22599 Use of a One-Way Hash with a Predictable Salt vulnerability in Inhandnetworks Inrouter302 Firmware and Inrouter615-S Firmware
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-760: Use of a One-way Hash with a Predictable Salt.
network
low complexity
inhandnetworks CWE-760
critical
9.1
2022-11-09 CVE-2022-25932 Unspecified vulnerability in Inhandnetworks Inrouter302 Firmware 3.5.37/3.5.4
The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474.
network
low complexity
inhandnetworks
critical
9.8
2022-05-12 CVE-2022-25995 Unspecified vulnerability in Inhandnetworks Ir302 Firmware 3.5.4
A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4.
network
low complexity
inhandnetworks
critical
9.0
2022-05-12 CVE-2022-26007 OS Command Injection vulnerability in Inhandnetworks Ir302 Firmware 3.5.4
An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4.
network
low complexity
inhandnetworks CWE-78
critical
9.0
2022-05-12 CVE-2022-26075 OS Command Injection vulnerability in Inhandnetworks Ir302 Firmware 3.5.37
An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37.
network
low complexity
inhandnetworks CWE-78
critical
9.0
2022-05-12 CVE-2022-26420 OS Command Injection vulnerability in Inhandnetworks Ir302 Firmware 3.5.37
An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37.
network
low complexity
inhandnetworks CWE-78
critical
9.0
2022-04-10 CVE-2022-27268 OS Command Injection vulnerability in Inhandnetworks Inrouter 900 Firmware
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory.
network
low complexity
inhandnetworks CWE-78
critical
9.8
2022-04-10 CVE-2022-27269 OS Command Injection vulnerability in Inhandnetworks Inrouter 900 Firmware
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn.
network
low complexity
inhandnetworks CWE-78
critical
9.8
2022-04-10 CVE-2022-27270 OS Command Injection vulnerability in Inhandnetworks Inrouter 900 Firmware
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets.
network
low complexity
inhandnetworks CWE-78
critical
9.8
2022-04-10 CVE-2022-27271 OS Command Injection vulnerability in Inhandnetworks Inrouter 900 Firmware
InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib.
network
low complexity
inhandnetworks CWE-78
critical
9.8