Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-38703: InHand Networks IR302, IR305, IR315, and IR615 firmware ZeroTier VPN Privilege Escalation
CVE-2026-38703
Summary
A security weakness in the ZeroTier VPN feature of InHand Networks' IR302, IR305, IR315, and IR615 firmware versions allows an attacker to gain complete control over a device connected to the network. This is a serious issue because it could be used to disrupt or take control of critical operations. InHand Networks should be contacted to obtain an updated, secure version of the firmware.
Original title
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earli...
Original description
A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firmware V1.0.118, IR315 firmware V1.0.118, IR615 firmware V1.0.118, and earlier versions. Attackers can exploit this vulnerability to obtain ROOT privileges on remote target devices.
Vulnerability type
CWE-77
Command Injection
Published: 28 May 2026 · Updated: 31 May 2026 · First seen: 28 May 2026