CVE-2026-38716
EUVD-2026-3791918.06.2026, 17:16
InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| inhandnetworks | ir915l-fq39-s_firmware | 𝑥 < 1.0.0.r20044 |
| inhandnetworks | ir912l-fq58_firmware | 𝑥 < 1.0.0.r20044 |
𝑥
= Vulnerable software versions