CVE-2021-38484

CRITICAL

InHand Networks IR615 Router <2.3.0.r4870 - RCE

Title source: llm
STIX 2.1

Description

InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or prevent an upload of malicious files to the server, which may allow an attacker, acting as an administrator, to upload malicious files. This could result in cross-site scripting, deletion of system files, and remote code execution.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-280-05

Scores

CVSS v3 9.1
EPSS 0.0065
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (2)
inhandnetworks/ir615_firmware 2.3.0.r4724
inhandnetworks/ir615_firmware 2.3.0.r4870
Published Oct 19, 2021
Tracked Since Feb 18, 2026